Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue is fixed in version 0.0.19.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55211.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55211.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "75962760189785990231656231754358255774",
"length": 816
},
"id": "CVE-2026-55211-2f619f9e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/equinor/surfio/commit/1619750bce28e39c4f378d2fb6d28b72380a12aa",
"target": {
"file": "src/lib/irap_import_ascii.cpp",
"function": "get_values"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"104068373432617526251695726916205565953",
"309115943093702837841694582758591206165",
"308265431350965122666885020501912935275",
"115187394084006026407330611967054410781",
"39245834873130807715957600413223223845"
],
"threshold": 0.9
},
"id": "CVE-2026-55211-40e093eb",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/equinor/surfio/commit/e009c0cad145484f854aeb22d1979f9216b291db",
"target": {
"file": "src/lib/irap_import_binary.cpp"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"204127681114991392854532631374309172295",
"280157379908924022736716678875737219335",
"237165629811663881258372494348804854918",
"39420228400719700218644215396683564347",
"330529729661760189718781453626246391462"
],
"threshold": 0.9
},
"id": "CVE-2026-55211-49fbd89f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/equinor/surfio/commit/1619750bce28e39c4f378d2fb6d28b72380a12aa",
"target": {
"file": "src/lib/irap_import_ascii.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "99701913567039314659509694515764363417",
"length": 619
},
"id": "CVE-2026-55211-4c52c624",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/equinor/surfio/commit/e009c0cad145484f854aeb22d1979f9216b291db",
"target": {
"file": "src/lib/irap_import_binary.cpp",
"function": "get_values_binary"
}
}
]
"2026-10-02T08:14:54Z"