Heap Buffer Overflow Vulnerability in openFPGALoader by Trabucayre
CVE-2026-35170
7.1HIGH
What is CVE-2026-35170?
A heap buffer overflow vulnerability exists in the BitParser::parseHeader() function of openFPGALoader, affecting versions 1.1.1 and earlier. This flaw can be triggered without the need for any FPGA hardware, allowing attackers to exploit the vulnerability by crafting a malicious .bit file, which could lead to out-of-bounds heap memory access. This issue poses a significant security risk, making it crucial for users to update their software to avoid potential exploitation.
Affected Version(s)
openFPGALoader <= 1.1.1
