Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-131 (缓冲区大小计算不正确) — Vulnerability Class 109

109 vulnerabilities classified as CWE-131 (缓冲区大小计算不正确). AI Chinese analysis included.

CWE-131 represents a critical logic error where software fails to accurately determine the necessary memory allocation size for a buffer. This miscalculation typically stems from using incorrect data types, ignoring header overhead, or neglecting null terminators during size computations. Attackers exploit this vulnerability by crafting inputs that exceed the allocated memory space, triggering a buffer overflow. This overflow allows malicious actors to overwrite adjacent memory, potentially executing arbitrary code, crashing the application, or gaining unauthorized system access. To prevent such exploits, developers must rigorously validate input lengths and employ safe, bounds-checking functions like strncpy or snprintf instead of unsafe alternatives. Additionally, utilizing static analysis tools and conducting thorough code reviews can help identify arithmetic errors in memory allocation logic before deployment, ensuring that buffer sizes accurately reflect the actual data requirements.

MITRE CWE Description
The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
Common Consequences (1)
Integrity, Availability, Confidentiality DoS: Crash, Exit, or Restart, Execute Unauthorized Code or Commands, Read Memory, Modify Memory
If the incorrect calculation is used in the context of memory allocation, then the software may create a buffer that is smaller or larger than expected. If the allocated buffer is smaller than expected, this could lead to an out-of-bounds read or write (CWE-119), possibly causing a crash, allowing a…
Mitigations (5)
Implementation When allocating a buffer for the purpose of transforming, converting, or encoding an input, allocate enough memory to handle the largest possible encoding. For example, in a routine that converts "&" characters to "&" for HTML entity encoding, the output buffer needs to be at least 5 times as large as the input buffer.
Implementation Understand the programming language's underlying representation and how it interacts with numeric calculation (CWE-681). Pay close attention to byte size discrepancies, precision, signed/unsigned distinctions, truncation, conversion and casting between types, "not-a-number" calculations, and how the language handles numbers that are too large or too small for its underlying representation. [REF-7]…
Implementation Perform input validation on any numeric input by ensuring that it is within the expected range. Enforce that the input meets both the minimum and maximum requirements for the expected range.
Architecture and Design For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.
Implementation When processing structured incoming data containing a size field followed by raw data, identify and resolve any inconsistencies between the size field and the actual size of the data (CWE-130).
Examples (2)
The following code allocates memory for a maximum number of widgets. It then gets a user-specified number of widgets, making sure that the user does not request too many. It then initializes the elements of the array using InitializeWidget(). Because the number of widgets can vary for each request, the code inserts a NULL pointer to signify the location of the last widget.
int i; unsigned int numWidgets; Widget **WidgetList; numWidgets = GetUntrustedSizeValue(); if ((numWidgets == 0) || (numWidgets > MAX_NUM_WIDGETS)) { ExitError("Incorrect number of widgets requested!"); } WidgetList = (Widget **)malloc(numWidgets * sizeof(Widget *)); printf("WidgetList ptr=%p\n", WidgetList); for(i=0; i<numWidgets; i++) { WidgetList[i] = InitializeWidget(); } WidgetList[numWidgets] = NULL; showWidgets(WidgetList);
Bad · C
The following image processing code allocates a table for images.
img_t table_ptr; /*struct containing img data, 10kB each*/ int num_imgs; ... num_imgs = get_num_imgs(); table_ptr = (img_t*)malloc(sizeof(img_t)*num_imgs); ...
Bad · C
CVE ID Title CVSS Severity Published
CVE-2026-104424 Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate — zebra 3.7 Low 2026-10-02
CVE-2026-102505 Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp - - 2026-10-01
CVE-2026-47578 NVIDIA Windows驱动内核缓冲区计算错误致代码执行 — GeForce 7.8 High 2026-09-30
CVE-2026-102729 OpenGFX主题加载函数越界写漏洞 — GUIX 5.9 Medium 2026-09-29
CVE-2026-13466 Unit Confusion in VAB Authentication — Trusted Firmware 8.1 High 2026-09-24
CVE-2026-88830 Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow — Red Hat Hardened Images 7.5 High 2026-09-23
CVE-2026-54692 SAIL: XBM X10 decoder writes 2 bytes per literal into a 1-byte-per-literal buffer (heap out-of-bounds write) — sail 7.8 High 2026-09-17
CVE-2026-91962 FreeRDP before 3.31.0 Integer Overflow via audin Apple backends — FreeRDP 6.3 Medium 2026-09-15
CVE-2026-47773 ArduinoBLE: Memory corruption via malformed ATT write request — ArduinoBLE 7.2 High 2026-09-11
CVE-2026-69598 Windows iSCSI Remote Code Execution Vulnerability — Windows 10 Version 1607 8.8 High 2026-09-08
CVE-2026-78221 OpenVPN 缓冲区错误漏洞 — OpenVPN 5.9 Medium 2026-09-07
CVE-2026-18743 Popt-devel: popt-static: short realloc in poptconfigfiletostring — popt 2.5 Low 2026-09-01
CVE-2026-78002 Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() function — Red Hat Enterprise Linux 10 7.5 High 2026-08-27
CVE-2026-44254 Wazuh: Stack Out-of-Bounds Write in remoted Decompression Path — wazuh 5.3 Medium 2026-08-19
CVE-2026-75093 sonos tract ONNX Initializer Loader tensor.rs from_raw_dt_align buffer size — tract 4.3 Medium 2026-08-18
CVE-2026-70457 rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg() — rsync 6.5 Medium 2026-08-13
CVE-2026-42170 Gimp: gimp dds plug-in heap-based buffer overflow via bpp mismatch in load_layer() (ddsread.c) — Red Hat Enterprise Linux 6 7.8 High 2026-08-08
CVE-2026-42169 Gimp: gimp apng loader heap-buffer-overflow when fctl width exceeds ihdr width (file-png.c) — Red Hat Enterprise Linux 9 7.3 High 2026-08-04
CVE-2026-45812 Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler — Apache NimBLE - - 2026-07-24
CVE-2026-45784 rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers — rust-openssl - - 2026-07-17
CVE-2026-55827 FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode — FreeRDP 7.5 High 2026-07-10
CVE-2026-0280 PAN-OS: IPv6 Firewall Policy Bypass — Cloud NGFW 1.7 Low 2026-07-09
CVE-2026-46521 ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression — ImageMagick 5.5 Medium 2026-06-10
CVE-2026-11604 OpenVPN ovpn-dco-win 安全漏洞 — ovpn-dco-win - - 2026-06-10
CVE-2026-42915 Microsoft Windows VMSwitch Denial of Service Vulnerability — Windows 10 Version 21H2 5.5 Medium 2026-06-09
CVE-2026-40618 BIG-IP SSL/TLS vulnerability — BIG-IP 7.5 High 2026-05-13
CVE-2026-44223 vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters — vllm 6.5 Medium 2026-05-12
CVE-2026-1949 Incorrect calculation of buffer size on the stack in AS320T — AS320T 9.8 Critical 2026-04-24
CVE-2026-41197 Brillig: Heap corruption in foreign call results with nested tuple arrays — noir 9.8AI Critical AI 2026-04-23
CVE-2026-40918 Gimp: gimp: denial of service via crafted pvr image file — Red Hat Enterprise Linux 6 5.5 Medium 2026-04-15

Vulnerabilities classified as CWE-131 (缓冲区大小计算不正确) represent 109 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.