Apache DataSketches C++(代码仓库:datasketches-cpp)中存在一个堆缓冲区溢出漏洞,发生在 HLL(HyperLogLog)草图反序列化过程中。 在 LIST 模式下反序列化草图时(无论是从字节缓冲区还是流中读取),程序会从输入中读取 coupon 计数,并直接将其用作向固定大小为 8 个条目的缓冲区中复制数据的条目数,而未对该计数值是否超过缓冲区容量进行检查。攻击者可构造恶意草图,导致程序在该内部堆缓冲区末尾之后最多写入 988 字节。这会破坏堆内存,引发程序崩溃,并可能为进一
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache DataSketches | 1.0.0-incubating≤ 5.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache DataSketches | 1.0.0-incubating ~ 5.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103636 | Apache DataSketches: datasketches-cpp: Out-of-bounds read in VarOpt union deserialization | |
| CVE-2026-103635 | Apache DataSketches: datasketches-cpp: Out-of-bounds read in compact Theta sketch deserial | |
| CVE-2026-103513 | Apache DataSketches: datasketches-cpp: Out-of-bounds read and write in the CPC sketch dese |
No comments yet