OSV-2025-267

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/tarantool/OSV-2025-267.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2025-267
Published
2025-04-08T00:17:16.034122Z
Modified
2025-07-23T14:22:40.655455Z
Summary
Stack-buffer-overflow in snap_usedef
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=408571331

Crash type: Stack-buffer-overflow WRITE {*}
Crash state:
snap_usedef
lj_snap_purge
lj_record_ins
References

Affected packages

OSS-Fuzz / tarantool

Package

Name
tarantool
Purl
pkg:generic/tarantool

Affected ranges

Type
GIT
Repo
https://github.com/tarantool/tarantool
Events

Affected versions

3.*
3.2.0
3.2.1
3.2.1-entrypoint
3.2.2-entrypoint
3.3.0
3.3.0-entrypoint
3.3.1
3.3.1-entrypoint
3.3.2
3.3.2-entrypoint
3.3.3-entrypoint
3.4.0
3.4.0-entrypoint
3.4.1-entrypoint
3.5.0-entrypoint

Ecosystem specific

{
    "severity": "HIGH"
}

Database specific

source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/tarantool/OSV-2025-267.yaml"
fixed_range
"d0242af36253b279f0fddd6887dfd89e679c175b:8c7cfb1cd0b3f5ce1d5b181403f68f7aaf657d9a"