Back

HIGH

blosc: heap-based buffer overflow when there is a lack of space to write compressed data

Published Nov 27, 2020

Description

blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data.

Affected products

Remediation

Red Hat statement

OpenShift Container Platform (OCP) 4 temporarily shipped one version of the blosc package in OCP 4.3.0. Updates to the blosc package, which is used in the ironic-hardware-inventory-recorder-image container are consumed from OpenStack Platform 16 repositories. In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP blosc package.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 27, 2020
Updated Aug 4, 2024
Reserved Nov 27, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 18, 2020
GHSA-8C7C-2C8J-3XFP