Buffer Overflow Vulnerability in Eclipse Reservoir Simulator Resdata Software
CVE-2026-55209

9.8CRITICAL

Key Information:

Vendor

Equinor

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-55209?

The resdata software, utilized for managing result files from the Eclipse reservoir simulator, is susceptible to multiple vulnerabilities due to inadequate validation of numeric fields, grid dimensions, keyword sizes, and array indexes when processing untrusted GRDECL files. This flaw, present in versions prior to 6.2.9, can lead to various issues such as buffer overflows, out-of-bounds reads, invalid array accesses, NULL pointer dereferences, memory corruption, and unexpected service termination. The issue is resolved in version 6.2.9, reinforcing the importance of updating to protect against these potential threats.

Affected Version(s)

resdata < 6.2.9

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.