CVE-2025-29476

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-29476
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-29476.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-29476
Published
2025-04-04T18:15:48Z
Modified
2025-04-06T20:49:01.474911Z
Summary
[none]
Details

Buffer Overflow vulnerability in compresschunkfuzzer with oss-fuzz on commit 16450518afddcb3139de627157208e49bfef6987 in c-blosc2 v.2.17.0 and before.

References

Affected packages

Debian:13 / c-blosc2

Package

Name
c-blosc2
Purl
pkg:deb/debian/c-blosc2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.17.1+ds-1

Affected versions

2.*

2.11.2+ds-1~exp1
2.12.0+ds-1
2.12.0+ds-2
2.13.1+ds-1
2.13.1+ds-1.1~exp1
2.13.1+ds-1.1
2.13.1+ds-2
2.13.1+ds-3
2.13.1+ds-4
2.13.1+ds-5
2.14.4+ds-1
2.14.4+ds-2
2.15.0+ds-1~exp1
2.15.0+ds-1
2.15.1+ds-1
2.15.2+ds-1
2.15.2+ds-2
2.15.2+ds-3
2.15.2+ds-4
2.15.2+ds-5
2.15.2+ds-6
2.16.0+ds-1
2.17.0+ds-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}