Heap Buffer Overflow in Apache DataSketches C++ Affects Multiple Versions
CVE-2026-103501
Currently unrated
What is CVE-2026-103501?
A significant heap buffer overflow vulnerability exists in the HLL sketch deserialization process of Apache DataSketches C++. When deserializing a sketch in LIST mode, the coupon count is improperly used as the number of entries copied into a fixed buffer of only 8 entries, without adequate capacity checks. This flaw allows for a crafted sketch to write up to 988 bytes beyond the heap buffer's limits. Such heap memory corruption can lead to application crashes and potentially expose the system to further exploitation risks. Users should upgrade to version 5.3.0, which rectifies this vulnerability.
Affected Version(s)
Apache DataSketches 1.0.0-incubating <= 5.2.0