Sceawere

Vulnerability Detail

CVE-2026-63209UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Signed Integer Overflow in compress

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
10h ago
Vendor
klauspost
Product
compress
Attack Type
CWE-190: Integer Overflow or Wraparound
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the overflowed negative repeat value causes an out-of-bounds memory access via unsafe.Pointer arithmetic, crashing the process with SIGSEGV. This issue has been patched in version 1.18.7.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-29T15:17:27.130Z",
  "pubdate": "2026-09-29T15:17:27.130Z",
  "executiveSummary": "A signed integer overflow vulnerability exists in the compress library, specifically within the s2.NewDict() function, affecting versions prior to 1.18.7.\nThe vulnerability allows an attacker to bypass repeat index validation mechanisms by providing a maliciously crafted dictionary containing a uvarint-encoded repeat value that exceeds the capacity of a signed 64-bit integer (MaxInt64).\nUpon calling Dict.Encode(), the overflow results in a negative integer representation, which subsequently leads to out-of-bounds memory access through improper unsafe.Pointer arithmetic.\nThe impact of this vulnerability is a process crash, resulting in a denial-of-service (DoS) condition via a SIGSEGV signal.\nExploitation requires an attacker to supply a specifically crafted dictionary to an application utilizing the affected component.\nThere are no specific authentication or privilege requirements stated beyond the ability to influence the input processed by the library.\nThe risk is categorized as high due to the potential for service disruption.",
  "technicalDetails": "The root cause of the vulnerability lies in improper handling of uvarint-encoded values within the s2.NewDict() function when constructing a dictionary for compression. The library fails to validate the upper bounds of a repeat index value against MaxInt64, permitting values that exceed the signed integer range.\nWhen a value exceeding MaxInt64 is provided, the signed integer overflow occurs during the assignment or processing phase. This transformation converts the expected positive magnitude into a negative value due to the wrapping behavior of fixed-width integer arithmetic.\nThe vulnerable code path involves the subsequent execution of Dict.Encode(). During this operation, the library utilizes the overflowed negative value in calculations related to memory offsets or indices. Because the value is negative, calculations involving unsafe.Pointer arithmetic are directed to invalid memory addresses located outside the bounds of allocated buffers.\nThe attack flow proceeds as follows: 1) An attacker crafts a malicious dictionary containing a uvarint-encoded repeat value larger than 9,223,372,036,854,775,807. 2) The attacker supplies this dictionary to an application function that invokes s2.NewDict(). 3) The function accepts the value without sufficient sanitization, causing the integer overflow to manifest internally. 4) The attacker triggers Dict.Encode(), forcing the library to perform illegal memory access using the corrupted, negative index value. 5) The operating system detects the illegal memory access (SIGSEGV), terminating the application process.\nThe issue is specific to the s2 compression dictionary handling logic. It demonstrates a lack of rigorous input boundary checking before performing memory-sensitive pointer operations. The use of unsafe.Pointer significantly exacerbates the impact, as it bypasses the standard memory safety guarantees provided by the Go runtime, leading directly to process instability rather than a managed panic or error state.\nThis vulnerability affects versions of the compress library prior to 1.18.7. Successful exploitation does not require advanced privileges or authentication, provided the attacker can submit input to an endpoint that leverages the vulnerable dictionary encoding process."
}
CVE-2026-63209: Signed Integer Overflow in compress (HIGH Severity, CVSS: 7.5) | Sceawere