Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue is fixed in version 0.0.19.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rcr2-hggw-43wm | surfio has an out-of-bounds read |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue is fixed in version 0.0.19. | |
| Title | surfio IRAP header size fields cause out-of-bounds reads | |
| Weaknesses | CWE-125 | |
| References |
|
|
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T15:28:59.014Z
Reserved: 2026-06-16T16:16:32.627Z
Link: CVE-2026-55211
No data.
Status : Received
Published: 2026-09-15T16:17:14.560
Modified: 2026-09-15T16:17:14.560
Link: CVE-2026-55211
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA