Impact
The vulnerability resides in the CipAppPath::deserialize_symbolic function of liftoff-sr CIPster, where an improper bounds check (CWE-119) allows data to be read beyond the intended memory region, creating an out-of-bounds read (CWE-125). This can expose sensitive information stored in adjacent memory. The attack vector is remote, as the application processes data that can be supplied from external sources.
Affected Systems
All versions of liftoff-sr CIPster that were released prior to the commit 886a4d090e1c5b0475f0b1c2fe0606a8f0d6a519 are affected. Because the project follows a rolling-release model, specific version numbers are not published; any deployment that has not incorporated this commit remains vulnerable. Administrators should verify that the source code is up to date with the patch commit before deployment.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, reflecting the potential for data leakage. The EPSS score of less than 1% suggests that exploitation is currently unlikely but not impossible. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed widespread exploitation. Nevertheless, because the flaw can be triggered remotely and the impact could involve sensitive data, the risk is non-negligible, especially in environments where CIPster processes confidential information.
OpenCVE Enrichment