CVE-2025-29476

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 120

Summary

CVE-2025-29476 is a newly discovered buffer overflow vulnerability that affects the compress_chunk_fuzzer function in c-blosc2 version 2.17.0 and older. This issue was identified during a fuzzing campaign using oss-fuzz. The buffer overflow occurs due to improper handling of user input, potentially leading to arbitrary code execution and security compromises. Users are urged to update their c-blosc2 installations as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share