Impact
ResData parses untrusted GRDECL files without performing adequate validation of numeric fields, grid dimensions, keyword sizes, and array indices. Malformed COORD, ZCORN, CORSNUM, ACTNUM, or MAPAXES data can reach parsing routines with inconsistent lengths and can trigger classic buffer overflows, out‑of‑bounds reads, invalid array access, NULL pointer dereferences, memory corruption, or service termination, providing an opportunity for arbitrary code execution or denial of service on the host system.
Affected Systems
Equinor’s ResData library, used for reading and writing result files from the Eclipse reservoir simulator, is vulnerable in all releases older than hosts a service capable of ingesting GRDECL files from untrusted sources is impacted.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity. The EPSS score is not available, so the likelihood of exploitation is uncertain, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote because a network service that processes GRDECL files can receive malicious data from external actors, and the failure conditions involve classic buffer overflows and other memory safety violations.
OpenCVE Enrichment
Github GHSA