OSV-2026-655

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/tarantool/OSV-2026-655.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2026-655
Published
2026-04-30T00:17:44.999830Z
Modified
2026-08-04T14:17:30.723869Z
Summary
Heap-buffer-overflow in lj_record_idx
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=507646002

Crash type: Heap-buffer-overflow WRITE 8
Crash state:
lj_record_idx
lj_record_ins
trace_state
References

Affected packages

OSS-Fuzz / tarantool

Package

Name
tarantool
Purl
pkg:generic/tarantool

Affected ranges

Type
GIT
Repo
https://github.com/tarantool/tarantool
Events

Affected versions

3.*
3.7.0
3.7.1
3.7.1-entrypoint
3.7.2-entrypoint
3.8.0
3.8.0-entrypoint
3.8.1-entrypoint
3.9.0-entrypoint

Ecosystem specific

{
    "severity": "HIGH"
}

Database specific

source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/tarantool/OSV-2026-655.yaml"
introduced_range
"83e12796838a74739ba35c740b0e21a442796ec7:dc969d16f6467569f4aa9dc124a31f023b803c22"