Impact
ResData, the library used to read and write Eclipse reservoir simulator result files, prior to version 6.2.9 performs insufficient validation of numeric fields, grid dimensions, keyword sizes, and array indexes while parsing untrusted GRDECL files in lib/resdata/rd_kw_grdecl.cpp and lib/resdata/rd_grid.cpp. Malformed COORD, ZCORN, CORSNUM, ACTNUM, or MAPAXES data can propagate to the allocation routine rd_grid_alloc_GRDECL_kw__ with inconsistent lengths, and an unbounded floating-point conversion can overflow the intended parser buffer. In a network service that accepts untrusted GRDECL files these conditions can trigger classic buffer overflows, out-of-bounds reads, invalid array accesses, NULL pointer dereferences, memory corruption, or service termination, allowing remote code execution or causing denial of service.
Affected Systems
Equinor’s ResData library, used for reading and writing result files from the Eclipse reservoir simulator, is vulnerable in all releases older than 6.2.9. Hosts that provide a service capable of ingesting GRDECL files from untrusted sources are impacted.
Risk and Exploitability
The CVSS score of 9.8 indicates the vulnerability is of high severity. The EPSS score of < 1% suggests a low probability of exploitation in the current environment, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, as a network service that processes GRDECL files can receive malicious data from external actors, and the failure conditions involve classic memory corruption bugs that can lead to code execution or denial of service.
OpenCVE Enrichment
Github GHSA