Bug#1149701: c-blosc2: CVE-2026-103222
Salvatore Bonaccorso
carnil at debian.org
Fri Oct 2 13:36:17 BST 2026
Source: c-blosc2
Version: 2.23.1+ds-2
X-Debbugs-CC: team at security.debian.org
Severity: important
Tags: upstream security
Hi,
The following vulnerability was published for c-blosc2.
CVE-2026-103222[0]:
| A vulnerability was determined in Blosc C-Blosc2 up to 3.3.2. This
| impacts the function blosclz_decompress of the file blosc/blosclz.c
| of the component blosclz Decompression. Executing a manipulation can
| lead to integer overflow. The attack may be launched remotely. A
| high complexity level is associated with this attack. The
| exploitability is said to be difficult. Upgrading to version 3.3.3
| will fix this issue. This patch is called
| fe2964d114d97847f56570a0ab2be2c57ccbeedc. The affected component
| should be upgraded.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-103222
https://www.cve.org/CVERecord?id=CVE-2026-103222
[1] https://github.com/Blosc/c-blosc2/commit/fe2964d114d97847f56570a0ab2be2c57ccbeedc
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
More information about the debian-science-maintainers
mailing list