CVE-2023-37188: Null Pointer Dereference
Published Dec 25, 2023
·Updated
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfpratedecompress at zfp/blosc2-zfp.c.
Affected Software
1 affected component
blosc C-Blosc2<2.9.3
Remediation
Patch Available
Event History
Dec 25, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-37188?
CVE-2023-37188 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2023-37188?
To fix CVE-2023-37188, upgrade C-blosc2 to version 2.9.3 or later.
3
What effects can CVE-2023-37188 have on my system?
CVE-2023-37188 can lead to a NULL pointer dereference, potentially causing application crashes.
4
Is there a workaround for CVE-2023-37188?
There are no known workarounds for CVE-2023-37188, the best course of action is to upgrade.
5
Which versions of C-blosc2 are affected by CVE-2023-37188?
CVE-2023-37188 affects all versions of C-blosc2 prior to 2.9.3.