CVE-2026-64197: Out Of Bounds Write when parsing a .DSB file in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DASYLabto a version that resolves this vulnerability.Fixed in 2026.0.0
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Users running DASYLab versions before 2026.0.0 are affected if they open a specially crafted .DSB file. Exploitation requires user interaction.
What does an attacker need to exploit the issue?
An attacker needs to persuade a user to open a malicious .DSB file in DASYLab. The supplied vector indicates local access and no privileges are required.
How can I determine whether my installation is affected?
Check the installed DASYLab version. Versions earlier than 2026.0.0 are affected.