CVE-2026-103222 Details
Description
A vulnerability was determined in Blosc C-Blosc2 up to 3.3.2. This impacts the function blosclz_decompress of the file blosc/blosclz.c of the component blosclz Decompression. Executing a manipulation can lead to integer overflow. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. Upgrading to version 3.3.3 will fix this issue. This patch is called fe2964d114d97847f56570a0ab2be2c57ccbeedc. The affected component should be upgraded.
An integer overflow vulnerability has been identified in Blosc C-Blosc2 versions prior to 3.3.2. The issue resides in the blosclz_decompress function within the blosc/blosclz.c file, specifically in the blosclz Decompression component. The vulnerability allows crafted input to cause an unbounded accumulation of match lengths, leading to heap-based buffer overflows. This issue can be exploited remotely, although it requires a high level of complexity.
Users should upgrade to Blosc C-Blosc2 version 3.3.3 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Blosc/c-blosc2/ | [email protected] | Vendor |
| https://github.com/Blosc/c-blosc2/commit/fe2964d114d97847f56570a0ab2be2c57ccbeedc | [email protected] | Source CodeVendor |
| https://github.com/Blosc/c-blosc2/releases/tag/v3.3.3 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-103222 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/954976 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/411905 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/411905/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-189 | Numeric Errors | [email protected] |
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Blosc C-Blosc2 | <= 3.3.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion