Integer Overflow in Blosc C-Blosc2 Decompression Functions
CVE-2026-103222

6.3MEDIUM

Key Information:

Vendor

Blosc

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-103222?

The Blosc C-Blosc2 library, specifically the blosclz_decompress function in the blosc/blosclz.c component, exhibits a vulnerability that allows for integer overflow under certain conditions. This can result in memory corruption, potentially leading to unauthorized manipulation. Although the exploit is complex and poses challenges for attackers, it remains a significant concern that could be triggered remotely. The issue is resolved in version 3.3.3, where the necessary patch (commit fe2964d114d97847f56570a0ab2be2c57ccbeedc) has been implemented. Users are encouraged to upgrade to this version to mitigate associated risks.

Affected Version(s)

C-Blosc2 3.3.0

C-Blosc2 3.3.1

C-Blosc2 3.3.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zzxzzb (VulDB User)
.