Impact
The vulnerability involves a reachable assertion in the align_order_members function of the Duplicate Symbol Handler. An attacker can trigger the assertion with crafted input, causing the compiler or any process using flatcc to abort and terminate, potentially leading to service disruption or code execution depending on the execution context.
Affected Systems
Dvidelabs flatcc versions up to and including 0.6.3 are affected. The issue is fixed by applying patch commit 8b19ba4e992ebcad7f5970704d1afc5507fa5205 or upgrading to a newer flatcc release that includes the fix.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The attack. The reachable assertion can lead to a denial of service or potential code execution if the vulnerable flatcc library is used in an exposed compiler service.
OpenCVE Enrichment