Mehrere Schwachstellen (CVE-2026-22886, CVE-2026-22891) in Biosig-Projekt
⚠️ CVE-Referenzen:
CVE-2026-22886
CVE-2026-22891
Zusammenfassung
In der Intan CLP-Parsing-Funktion der libbiosig-Bibliothek des BiOSig-Projekts, Version 3.9.2 und Master Branch (db9a9a63), wurde eine kritische Heap-basierte Pufferüberlauf-Sicherheitslücke entdeckt (CVE-2026-22891). Angreifer können diese Schwachstelle ausnutzen, indem sie eine speziell präparierte Intan CLP-Datei einschleusen, um beliebigen Schadcode auszuführen und so die Sicherheit und Integrität der betroffenen Systeme zu kompromittieren. Ein Patch ist dringend erforderlich.
The BiOSig Project - LibbiOSig - CRITICAL - CVE-2026-22891.
A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of libbiosig, version 3.9.2 and the Master Branch (db9a9a63). This vulnerability can be exploited by providing a specially crafted Intan CLP file, which may lead to arbitrary code execution on the affected system. Attackers could leverage this flaw to execute malicious code, thereby compromising the security and integrity of the application.
Quelle: securityvulnerability.io