Back

HIGH

Integer Overflow or Wraparound and Out-of-bounds Write in compress

Published Sep 29, 2026

Description

compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the overflowed negative repeat value causes an out-of-bounds memory access via unsafe.Pointer arithmetic, crashing the process with SIGSEGV. This issue has been patched in version 1.18.7.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 29, 2026
Updated Sep 29, 2026
Reserved Jul 15, 2026
CISA Vulnrichment
Updated Sep 29, 2026
NVD
Status Received
Modified Sep 29, 2026
Red Hat
Severity Important
Public date Sep 29, 2026