Impact
The vulnerability is a missing Release of Memory after the Effective Lifetime in the Is-Daouda is-Engine library, which causes a memory leak. The continuous accumulation of unreleased memory can exhaust system resources, leading to degraded performance or crashes. The weakness is defined as CWE‑401, a classic memory leak, affecting confidentiality or integrity only if the leaked memory contains sensitive data, but the primary impact is availability.
Affected Systems
Is‑Daouda is‑Engine versions prior to 3.3.4 are affected. No other vendors or product versions are listed.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or through exposed application interfaces; the description does not specify network exposure, so this is inferred. An attacker could potentially trigger resource exhaustion by inducing the application to allocate large or frequent memory blocks, leading to service disruption.
OpenCVE Enrichment