Description
Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue is fixed in version 0.0.19.
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Out‑of‑Bounds Read leading to buffer overflow
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in Surfio, a library that reads and writes surface files, due to inadequate validation of size fields in IRAP files before version 0.0.19. When an attacker supplies an IRAP file with size fields that exceed the buffer size, Surfio performs an out‑of‑bounds read, causing a buffer overflow. The flaw allows the attacker to corrupt memory, potentially leading to denial of service or arbitrary code execution, especially when the library parses untrusted files in a networking context such as a web service. This issue is fixed in Surfio 0.0.19. The weakness is a classic out‑of‑bounds read (CWE‑125).

Affected Systems

Equinor’s Surfio library is affected. Versions earlier than 0.0.19 contain the flaw. Any deployment that imports or writes IRAP surface files using Surfio before the 0.0.19 release is vulnerable. This includes services that parse user‑supplied surface data over a network, such as web applications or back‑end processing pipelines that rely on Surfio.

Risk and Exploitability

The CVSS base score is 9.8, signaling critical severity. The EPSS score is < 1%, indicating a very low exploitation probability, and the flaw is not listed in the CISA KEV catalogue. The most likely attack vector is through a remote network service that processes untrusted IRAP files. Exploitation requires parsing the malicious file. Because the payload can be delivered remotely, and the impact could be execution of arbitrary code or denial of service, the risk to organizations remains high until the upgrade is applied.

Generated by OpenCVE AI on September 20, 2026 at 16:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Surfio release 0.0.19 or later, ensuring the library’s validation of IRAP size fields is present.
  • Audit all code paths that ingest surface data to confirm that only trusted sources are processed, or refactor to isolate untrusted parsing.
  • Disable or remove any functionality that parses IRAP files from external or user‑supplied sources until the upgrade is deployed, and monitor logs for anomalous read attempts.

Generated by OpenCVE AI on September 20, 2026 at 16:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-rcr2-hggw-43wm surfio has an out-of-bounds read
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Equinor
Equinor surfio
Vendors & Products Equinor
Equinor surfio

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue is fixed in version 0.0.19.
Title surfio IRAP header size fields cause out-of-bounds reads
Weaknesses CWE-125
References
Metrics cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T15:17:43.320Z

Reserved: 2026-06-16T16:16:32.627Z

Link: CVE-2026-55211

cve-icon Vulnrichment

Updated: 2026-09-17T15:17:38.271Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:14.560

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses