CVE-2026-64198: Out Of Bounds Read in file handling when parsing a .DSB file in DASYLab
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a few bytes past the end of an allocated heap buffer during file handling. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DASYLabto a version that resolves this vulnerability.Fixed in 2026.0.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of DASYLab versions before 2026.0.0 are exposed if they open a specially crafted .DSB file. Exploitation is local and requires user interaction.
What does an attacker need to exploit the vulnerability?
An attacker must create a malicious .DSB file and persuade a user to open it in DASYLab. No privileges are required before exploitation, but the user must interact with the file.
Which versions should be remediated?
All DASYLab versions before 2026.0.0 are affected. Update to version 2026.0.0 or later.