CVE-2023-28638 is a buffer overrun vulnerability in Snappier 1.1.0, a C# implementation of the Snappy compression algorithm. This flaw arises from a specific interaction between byte references and the .NET garbage collector during compaction, where brief invalid byte reference states can lead to incorrect buffer range checks. The vulnerability has a CVSS score of 5.9 (Medium), indicating a network-based attack with high attack complexity, requiring precise timing for a successful denial-of-service impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE. Users are advised to upgrade to Snappier 1.1.1 or implement buffer pinning as a partial mitigation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.0CPE matchmatch criteria | cpe:2.3:a:snappier_project:snappier:1.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.