Impact
Uncontrolled recursion is triggered when Samsung’s rlottie library processes serialized data that contains nested payloads. The resulting recursive calls can exhaust stack or memory resources, leading to a crash and a denial of service or application instability. The weakness stems from insufficient validation of nesting depth, which is reflected in CWE-674.
Affected Systems
The affected product is Samsung Open Source rlottie, for all versions prior to the code commit 8de0d9e6ca80ffef654965505981727b9fa06a51. Users of any earlier release of rlottie must review the commit history to determine if they are impacted.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available, so the current likelihood of exploitation is unknown. Because the vulnerability requires malicious serialized input, the attack vector is inferred to be a local or remote scenario where an attacker can supply crafted data to an application that uses rlottie. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment