Intel

AIKIDO-2026-490744

github.com/supranational/blst is vulnerable to Out-of-bounds Write

Out-of-bounds WriteCVE-2026-2681 Published 5 days ago

53

Medium Risk

This Affects:

GOgithub.com/supranational/blst
0.0.1 - 0.3.16
Fixed in 0.3.17
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Out-of-bounds Write via the blst_sha256_bcopy assembly routine. An attacker can cause memory corruption and terminate the process by supplying a zero-length salt parameter.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/supranational/blst is vulnerable to Out-of-bounds Write in versions 0.0.1 - 0.3.16.

How to fix this

Upgrade the github.com/supranational/blst library to the patch version.