Impact
A memory leak exists in the fb_clear_parser function of flatcc, a library used to parse FlatBuffer data. The flaw allows repeated allocations without corresponding releases, which can cause a process to consume increasing amounts of memory and eventually crash or become unresponsive. The vulnerability is formally identified as CWE-401 and CWE-404.
Affected Systems
The vulnerability affects Dvidelabs flatcc versions up to and including 0.6.3. The flaw can be triggered by supplying crafted input to the parser, and any project that incorporates flatcc to parse data may be impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, combining medium impact with a remote attack vector. The EPSS score is below 1 %, suggesting a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, the exploit has been publicly disclosed and can be used against exposed services that accept external FlatBuffer input.
OpenCVE Enrichment