PT-2024-21293 · Cbor2+1 · Cbor2+1

Miri64

·

Published

2024-02-19

·

Updated

2025-12-10

·

CVE-2024-26134

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions cbor2 versions 5.5.1 through 5.6.2
Description The issue concerns a denial-of-service vulnerability in cbor2, which provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. An attacker can crash a service using cbor2 to parse a CBOR binary by sending a long enough object.
Recommendations For versions 5.5.1 through 5.6.2, update to version 5.6.2 or later, which contains a patch for this issue. As a temporary workaround, consider restricting the size of CBOR objects that can be parsed to prevent crashes.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-26134
GHSA-375G-39JQ-VQ7M
OPENSUSE-SU-2025:14733-1
OPENSUSE-SU-2025:20133-1
PYSEC-2024-155
SUSE-SU-2025:21168-1
SUSE-SU-2025_21168-1

Affected Products

Suse
Cbor2