PT-2024-21293 · Cbor2+1 · Cbor2+1
Miri64
·
Published
2024-02-19
·
Updated
2025-12-10
·
CVE-2024-26134
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
cbor2 versions 5.5.1 through 5.6.2
Description
The issue concerns a denial-of-service vulnerability in cbor2, which provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. An attacker can crash a service using cbor2 to parse a CBOR binary by sending a long enough object.
Recommendations
For versions 5.5.1 through 5.6.2, update to version 5.6.2 or later, which contains a patch for this issue. As a temporary workaround, consider restricting the size of CBOR objects that can be parsed to prevent crashes.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Cbor2