PT-2019-14587 · Lmdb+2 · Py-Lmdb+2

CVE-2019-16224

·

Published

2019-09-11

·

Updated

2026-03-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions py-lmdb version 0.97
Description An issue was discovered in py-lmdb where for certain values of md flags, the mdb node add function does not properly set up a memcpy destination, leading to an invalid write operation. This issue occurs when accessing a data.mdb file supplied by an attacker.
Recommendations For py-lmdb version 0.97, consider restricting access to untrusted data.mdb files until a patch is available. As a temporary workaround, avoid using the mdb node add function with unverified input.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2146
ALT-PU-2022-2549
CVE-2019-16224
ECHO-5860-4D3A-E18C
GHSA-9Q62-R72G-PVV7
OPENSUSE-SU-2026:10430-1
PYSEC-2019-236

Affected Products

Alt Linux
Debian
Py-Lmdb