{"id":"CVE-2025-52935","summary":"Integer Overflow or Wraparound vulnerability in dragonflydb/dragonfly","details":"Integer Overflow or Wraparound vulnerability in dragonflydb dragonfly (src/redis/lua/struct modules). This vulnerability is associated with program files lua_struct.C.\n\nThis issue affects dragonfly: 1.30.1, 1.30.0, 1.28.18.","modified":"2026-08-12T15:13:57.498217Z","published":"2025-06-23T09:27:18.355Z","database_specific":{"cna_assigner":"GovTech CSG","cwe_ids":["CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52935.json","unresolved_ranges":[{"extracted_events":[{"introduced":"1.28.18"},{"last_affected":"1.28.18"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52935.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-52935"},{"type":"FIX","url":"https://github.com/dragonflydb/dragonfly/commit/473e002c848eb312f23d84114eb4951a7c4af5a1"},{"type":"FIX","url":"https://github.com/dragonflydb/dragonfly/pull/4996"},{"type":"PACKAGE","url":"https://github.com/dragonflydb/dragonfly"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dragonflydb/dragonfly","events":[{"introduced":"fd4f7027f77fbe49e79d0b94e2f892234e388208"},{"fixed":"473e002c848eb312f23d84114eb4951a7c4af5a1"}],"database_specific":{"extracted_events":[{"introduced":"1.30.1"},{"last_affected":"1.30.1"},{"introduced":"1.30.0"},{"last_affected":"1.30.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.30.0","1.30.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52935.json","vanir_signatures_modified":"2026-08-12T15:13:57Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"212353940668053933632077966106377345980","length":380},"id":"CVE-2025-52935-0a151cef","signature_type":"Function","signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/473e002c848eb312f23d84114eb4951a7c4af5a1","target":{"file":"src/redis/lua/struct/lua_struct.c","function":"getnum"}},{"id":"CVE-2025-52935-188358e6","signature_type":"Function","signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/473e002c848eb312f23d84114eb4951a7c4af5a1","target":{"file":"src/redis/lua/struct/lua_struct.c","function":"controloptions"},"deprecated":false,"digest":{"function_hash":"209148936099144138409285023791391343778","length":543}},{"digest":{"line_hashes":["252260118326799049191156181394685749318","140212443415647500912109205308826769500","47010833300303086681847101454590249461","2250722161879345816330442566485950611","291778318289862582589671380180879160640","334836077840905045155583947536240977132","75257252756429438366239461806916592544","328810329053557788914453396839483306372","128854904967302558653028066436045146216","18412046823770042382161477427479286047","61915029324611414734672095656655490873","194538167452478719857363951948039156123","219285841976367303374237696455245299327","130487431531773260282343331813662805546","62896359733481919104079431318740588747","79844671906440840823825256474367351454","82136349130077275828760951476966216953","322234568658267143906843575519826420808","139114028757505796482812688056023538966","289225860499092828678937269241542432163","77797580407604165072230177310498680959"],"threshold":0.9},"id":"CVE-2025-52935-673c3c3d","signature_type":"Line","signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/473e002c848eb312f23d84114eb4951a7c4af5a1","target":{"file":"src/redis/lua/struct/lua_struct.c"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"145616438999787387902890994110005036109","length":663},"id":"CVE-2025-52935-87157e30","signature_type":"Function","signature_version":"v1","source":"https://github.com/dragonflydb/dragonfly/commit/473e002c848eb312f23d84114eb4951a7c4af5a1","target":{"file":"src/redis/lua/struct/lua_struct.c","function":"optsize"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/V:C/RE:M/U:Red"}]}