Impact
The vulnerability exists in Surfio, a library that reads and writes surface files, due to inadequate validation of size fields in IRAP files before version 0.0.19. When an attacker supplies an IRAP file with size fields that exceed the buffer size, Surfio performs an out‑of‑bounds read, causing a buffer overflow. The flaw allows the attacker to corrupt memory, potentially leading to denial of service or arbitrary code execution, especially when the library parses untrusted files in a networking context such as a web service. This issue is fixed in Surfio 0.0.19. The weakness is a classic out‑of‑bounds read (CWE‑125).
Affected Systems
Equinor’s Surfio library is affected. Versions earlier than 0.0.19 contain the flaw. Any deployment that imports or writes IRAP surface files using Surfio before the 0.0.19 release is vulnerable. This includes services that parse user‑supplied surface data over a network, such as web applications or back‑end processing pipelines that rely on Surfio.
Risk and Exploitability
The CVSS base score is 9.8, signaling critical severity. The EPSS score is < 1%, indicating a very low exploitation probability, and the flaw is not listed in the CISA KEV catalogue. The most likely attack vector is through a remote network service that processes untrusted IRAP files. Exploitation requires parsing the malicious file. Because the payload can be delivered remotely, and the impact could be execution of arbitrary code or denial of service, the risk to organizations remains high until the upgrade is applied.
OpenCVE Enrichment
Github GHSA