OSV-2021-422

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/c-blosc2/OSV-2021-422.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2021-422
Published
2021-02-20T00:01:08.633490Z
Modified
2022-04-13T03:04:40.233181Z
Summary
Heap-use-after-free in frame_get_lazychunk
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=31120

Crash type: Heap-use-after-free READ 4
Crash state:
frame_get_lazychunk
frame_decompress_chunk
blosc2_schunk_decompress_chunk
References

Affected packages

OSS-Fuzz / c-blosc2

Package

Name
c-blosc2
Purl
pkg:generic/c-blosc2

Affected ranges

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

{
    "fixed_range": "969fb4cbb617801876fb5ddefc73778935ff1a56:81c2fcd59368a9c57da77416066e731a7183a57d"
}