Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57585

Опубликовано: 30 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.

A flaw was found in MessagePack for Python, a serializer implementation. This vulnerability, categorized as a Use-After-Free (CWE-416), occurs when the Unpacker component is reused after an error. A remote attacker could exploit this by repeatedly providing untrusted input, leading to an out-of-bounds read and a system crash. This can result in a Denial of Service (DoS) attack.

Отчет

This Important flaw in MessagePack for Python can lead to a denial of service. An out-of-bounds read and subsequent process crash may occur if an Unpacker instance is reused after an error has been caught, potentially allowing an attacker to disrupt services that process MessagePack data.

Меры по смягчению последствий

To mitigate this issue, applications utilizing MessagePack for Python should be reviewed to ensure that Unpacker instances are not reused after an error has occurred during unpacking. Instead, a new Unpacker instance should be created for subsequent operations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Not affected
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Not affected
Red Hat AI Inference Serverrhaii/vllm-cuda-rhel9Not affected
Red Hat AI Inference Serverrhaii/vllm-gaudi-rhel9Not affected
Red Hat AI Inference Serverrhaii/vllm-rocm-rhel9Not affected
Red Hat AI Inference Serverrhaii/vllm-tpu-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2496020msgpack: MessagePack for Python: Denial of Service via Unpacker reuse after error

EPSS

Процентиль: 41%
0.00488
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.

CVSS3: 7.5
nvd
3 месяца назад

MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.

CVSS3: 7.5
msrc
3 месяца назад

MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught error

CVSS3: 7.5
debian
3 месяца назад

MessagePack is the serializer implementation for Python msgpack.org. P ...

suse-cvrf
2 месяца назад

Security update for python-msgpack

EPSS

Процентиль: 41%
0.00488
Низкий

7.5 High

CVSS3