Intel

AIKIDO-2026-644423

MessagePack is vulnerable to Integer Overflow

Integer OverflowGHSA-7rj2-5w9w-r9jx Published Yesterday

75

High Risk

This Affects:

DOTNETMessagePack
0.0.1 - 2.5.306
Fixed in 2.5.307
3.0.0 - 3.1.10
Fixed in 3.1.11
Are you affected? Scan for Free

TL;DR

MessagePack's LZ4 block decompressor accumulates literal and match lengths from length extension bytes inside an unchecked block, with no check for int32 overflow. When an application enables Lz4Block or Lz4BlockArray compression and deserializes untrusted MessagePack data, a crafted payload around 8.4 MB can wrap the length accumulator to a large negative value, corrupting pointer arithmetic and triggering an out-of-bounds memory access that crashes the process. The patch validates the accumulated length against the remaining output buffer before every addition and before copying literals or a repeated sequence, rejecting malformed input instead of overflowing.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you enable LZ4 compression (Lz4Block or Lz4BlockArray) while deserializing untrusted MessagePack data.

Background info

MessagePack is vulnerable to Integer Overflow in versions 0.0.1 - 2.5.306 and 3.0.0 - 3.1.10.

How to fix this

Upgrade the MessagePack library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform