Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8j3x-m868-cpw8

Опубликовано: 30 июн. 2026
Источник: github
Github: Прошло ревью
CVSS4: 1.9
CVSS3: 7.8

Описание

Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow

Summary

A memory-safety vulnerability in Open Babel's bundled zipstream decompression code caused an out-of-bounds write via overlapping memcpy when reading a crafted gzip-compressed chemistry file.

Details

The flaw was in basic_unzip_streambuf::underflow. The decompression buffer refill path invoked memcpy with overlapping source and destination regions, which is undefined behavior and produced out-of-bounds writes in practice. Any file format read through the gzip-wrapped reader was a potential trigger.

Impact

Open Babel is a C++ library and CLI used to read and write chemistry file formats; it is shipped by Linux distributions and embedded in services that may parse untrusted input. Triggering this vulnerability requires the victim to open a malicious gzip-compressed chemistry file with the obabel tool, the OBConversion API, or any of the language bindings (Python, Ruby, Java, R, Perl, C#, PHP).

Affected versions

All releases up to and including 3.1.1.

Patched version

3.2.0 (released 2026-05-26).

Patch

Fix commit: https://github.com/openbabel/openbabel/commit/d4621d41 Originally reported as #2832; fixes consolidated in #2913.

A minimized reproducer for this CVE is checked in under test/files/fuzz_regress/ and is exercised on every CI build under ASAN+UBSAN by the fuzzregresstest harness.

Credit

Reported via OSS-Fuzz.

Пакеты

Наименование

openbabel

pip
Затронутые версииВерсия исправления

< 3.2.0

3.2.0

EPSS

Процентиль: 14%
0.00232
Низкий

1.9 Low

CVSS4

7.8 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 5.3
ubuntu
10 месяцев назад

A security vulnerability has been detected in Open Babel up to 3.1.1. This vulnerability affects the function zlib_stream::basic_unzip_streambuf::underflow in the library /src/zipstreamimpl.h. Such manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used.

CVSS3: 5.3
nvd
10 месяцев назад

A security vulnerability has been detected in Open Babel up to 3.1.1. This vulnerability affects the function zlib_stream::basic_unzip_streambuf::underflow in the library /src/zipstreamimpl.h. Such manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used.

CVSS3: 5.3
debian
10 месяцев назад

A security vulnerability has been detected in Open Babel up to 3.1.1. ...

CVSS3: 7.8
fstec
10 месяцев назад

Уязвимость функции zlib_stream::basic_unzip_streambuf::underflow программного обеспечения преобразования форматов файлов химических веществ Open Babel, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.8
redos
9 месяцев назад

Множественные уязвимости xdrawchem

EPSS

Процентиль: 14%
0.00232
Низкий

1.9 Low

CVSS4

7.8 High

CVSS3

Дефекты

CWE-787