MessagePack is vulnerable to Integer Overflow
75
High Risk
MessagePack's LZ4 block decompressor accumulates literal and match lengths from length extension bytes inside an unchecked block, with no check for int32 overflow. When an application enables Lz4Block or Lz4BlockArray compression and deserializes untrusted MessagePack data, a crafted payload around 8.4 MB can wrap the length accumulator to a large negative value, corrupting pointer arithmetic and triggering an out-of-bounds memory access that crashes the process. The patch validates the accumulated length against the remaining output buffer before every addition and before copying literals or a repeated sequence, rejecting malformed input instead of overflowing.
You are affected if you are using a version that falls within the vulnerable range and you enable LZ4 compression (Lz4Block or Lz4BlockArray) while deserializing untrusted MessagePack data.
MessagePack is vulnerable to Integer Overflow in versions 0.0.1 - 2.5.306 and 3.0.0 - 3.1.10.
Upgrade the MessagePack library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.