CVE-2025-50343

NameCVE-2025-50343
DescriptionAn issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the fields array. This leads to out-of-bounds reads and invalid memory frees during cleanup, potentially causing a segmentation fault or heap corruption.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4459-1, DLA-4644-1
Debian Bugs1124797

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libmatio (PTS)bookworm, bookworm (security)1.5.23-2+deb12u1fixed
trixie1.5.28-2vulnerable
forky1.5.30-4fixed
sid1.6.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libmatiosourceexperimental1.5.30-1
libmatiosourcebullseye1.5.19-2+deb11u1DLA-4459-1
libmatiosourcebookworm1.5.23-2+deb12u1DLA-4644-1
libmatiosource(unstable)1.5.30-2unimportant1124797

Notes

https://github.com/tbeu/matio/issues/275
Fixed by: https://github.com/tbeu/matio/commit/41b505410dafaa236b61b52c7910d4c4831404f2
https://github.com/tbeu/matio/issues/275#issuecomment-5821819184
CVE is disputed, the error is on the caller side, maintainer only hanged the
API to Mat_VarCreateStruct2().

Search for package or bug name: Reporting problems