Buffer Overflow Vulnerability in c-blosc2 Products by Blosc
CVE-2025-29476

5.5MEDIUM

Key Information:

Vendor

Blosc

Status
Vendor
CVE Published:
4 April 2025

What is CVE-2025-29476?

A buffer overflow vulnerability has been identified in the compress_chunk_fuzzer component of c-blosc2, specifically in versions up to and including 2.17.0. This flaw stems from an improper handling of input data, which can lead to memory corruption, potentially allowing an attacker to execute arbitrary code or crash the application. Developers utilizing c-blosc2 in their systems are advised to review the latest updates and apply necessary patches to mitigate risks.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.