Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-82797

Опубликовано: 31 авг. 2026
Источник: redhat
CVSS3: 5.5

Описание

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.

A flaw was found in rlottie. This uncontrolled recursion vulnerability allows a local attacker to cause a denial of service (DoS) by providing specially crafted serialized data with nested payloads. Successful exploitation requires user interaction to process the malicious data.

Отчет

The rlottie library is shipped in Fedora and EPEL community distributions. The uncontrolled recursion vulnerability can be triggered by processing specially crafted serialized data with nested payloads, leading to a denial of service.

Меры по смягчению последствий

Update rlottie to a version that includes the upstream fix commit 8de0d9e6ca80ffef654965505981727b9fa06a51.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1265
https://bugzilla.redhat.com/show_bug.cgi?id=2526268rlottie: rlottie: Denial of Service via uncontrolled recursion with serialized data

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
16 дней назад

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.

CVSS3: 5.5
nvd
16 дней назад

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.

CVSS3: 5.5
debian
16 дней назад

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie al ...

CVSS3: 5.5
github
16 дней назад

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.

5.5 Medium

CVSS3