Impact
The vulnerability is an out‑of‑bounds read in the table‑leaf page reader of Turso. The code uses a cell‑count field supplied by an attacker‑controlled database file, without performing bounds validation. By crafting a malicious database with an altered cell count, an attacker can trigger an index‑out‑of‑bounds panic when the file is queried, causing the application to crash and resulting in denial of service.
Affected Systems
Affected systems are installations of Turso database software through version 0.8.0-pre.8. These include any application that uses the Turso core storage module up to that pre‑release. The vendors affected are tursodatabase's Turso product.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. Exploit availability is unclear because the EPSS score is not reported and the vulnerability is not listed in the CISA KEV catalog. Attackers likely need access to the victim’s file system to place a crafted database or must deliver the file through an unsecured input channel. If successful, the attack results in a crash that renders the application unavailable until restarted, which can disrupt services or deny access to legitimate users.
OpenCVE Enrichment