rootpwn

critical · CVSS v3 9.8 · CVSS v4 5.1

CVE-2026-79113

OpenAPV versions prior to 1.1.1.0 contain a heap-based buffer overflow in the read_bitstream function, allowing attackers to corrupt memory

Overview

OpenAPV versions prior to 1.1.1.0 contain a heap-based buffer overflow in the read_bitstream function, allowing attackers to corrupt memory and potentially execute arbitrary code. This flaw can be exploited remotely by sending crafted data to vulnerable systems. The vulnerability is critical, with a CVSS v3 score of 9.8.

Description

OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.

Impact

The buffer overflow can lead to arbitrary code execution, compromising confidentiality, integrity, and availability of the affected system. System administrators and security teams are directly impacted as they must address the vulnerability to protect infrastructure.

Remediation

Apply the official patch to upgrade to OpenAPV 1.1.1.0 or later. If patching is not immediately possible, restrict network access to the read_bitstream endpoint, disable the feature if unused, and enable memory protection mechanisms such as ASLR and stack canaries.

Risk context

The vulnerability is classified as critical with a CVSS v3 score of 9.8, indicating a high urgency for remediation. No EPSS score is available, but the severity alone warrants immediate action.

Affected products

  • OpenAPV

Scores

Severity
critical
CVSS v2
7.5
CVSS v3
9.8
CVSS v4
5.1
EPSS
—

buffer-overflow heap critical OpenAPV read_bitstream patch defense

← All CVEs