CVE-2026-64196: Out Of Bounds Write when parsing a .DSB file in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DASYLabto a version that resolves this vulnerability.Fixed in 2026.0.0 - Compensating control
Mitigate exploitation by preventing users from opening untrusted or specially crafted .DSB files (e.g., restrict/scan incoming .DSB files before opening).