以下是该漏洞描述信息的中文翻译: Apache DataSketches C++ 仓库(datasketches-cpp)中 CPC sketch 反序列化过程存在越界读取和越界写入漏洞。 通过字节缓冲区或流传递给 的恶意构造的序列化 CPC sketch 数据,可导致解压缩器在压缩数据结束后仍继续读取,因为在解码完成之后才检查读取位置。在混合模式(hybrid flavor)下,由于未对解码后的行索引进行验证,还可能引发对内部堆缓冲区的越界写入。此外,若干其他头部字段和解码值(包括 )也未经过验证。这可能导致堆内
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache DataSketches | 2.0.0-incubating≤ 5.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache DataSketches | 2.0.0-incubating ~ 5.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103636 | Apache DataSketches: datasketches-cpp: Out-of-bounds read in VarOpt union deserialization | |
| CVE-2026-103635 | Apache DataSketches: datasketches-cpp: Out-of-bounds read in compact Theta sketch deserial | |
| CVE-2026-103501 | Apache DataSketches: datasketches-cpp: HLL CouponList Deserialization Buffer Overflow allo |
No comments yet