Integer Overflow in Blosc C-Blosc2 Decompression Functions
CVE-2026-103222
6.3MEDIUM
What is CVE-2026-103222?
The Blosc C-Blosc2 library, specifically the blosclz_decompress function in the blosc/blosclz.c component, exhibits a vulnerability that allows for integer overflow under certain conditions. This can result in memory corruption, potentially leading to unauthorized manipulation. Although the exploit is complex and poses challenges for attackers, it remains a significant concern that could be triggered remotely. The issue is resolved in version 3.3.3, where the necessary patch (commit fe2964d114d97847f56570a0ab2be2c57ccbeedc) has been implemented. Users are encouraged to upgrade to this version to mitigate associated risks.
Affected Version(s)
C-Blosc2 3.3.0
C-Blosc2 3.3.1
C-Blosc2 3.3.2
