{"id":"CVE-2026-103222","summary":"Blosc C-Blosc2 blosclz Decompression blosclz.c blosclz_decompress integer overflow","details":"A vulnerability was determined in Blosc C-Blosc2 up to 3.3.2. This impacts the function blosclz_decompress of the file blosc/blosclz.c of the component blosclz Decompression. Executing a manipulation can lead to integer overflow. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. Upgrading to version 3.3.3 will fix this issue. This patch is called fe2964d114d97847f56570a0ab2be2c57ccbeedc. The affected component should be upgraded.","modified":"2026-10-02T08:11:36.344653Z","published":"2026-09-30T14:00:10.446Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-189","CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103222.json"},"references":[{"type":"WEB","url":"https://github.com/Blosc/c-blosc2/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103222.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103222"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-103222"},{"type":"ADVISORY","url":"https://vuldb.com/submit/954976"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/411905"},{"type":"REPORT","url":"https://vuldb.com/vuln/411905/cti"},{"type":"FIX","url":"https://github.com/Blosc/c-blosc2/commit/fe2964d114d97847f56570a0ab2be2c57ccbeedc"},{"type":"FIX","url":"https://github.com/Blosc/c-blosc2/releases/tag/v3.3.3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/blosc/c-blosc2","events":[{"introduced":"7265419b23872707b1b52298d5f1469c9ea7b9e7"},{"fixed":"fe2964d114d97847f56570a0ab2be2c57ccbeedc"},{"fixed":"681c1d97435a8528e01da205c9bef27521e7ae02"}],"database_specific":{"extracted_events":[{"introduced":"3.3.0"},{"last_affected":"3.3.0"},{"introduced":"3.3.1"},{"last_affected":"3.3.1"},{"introduced":"3.3.2"},{"last_affected":"3.3.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["3.3.0","3.3.1","3.3.2","v3.3.2","v3.3.1","v3.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103222.json","vanir_signatures_modified":"2026-10-02T08:11:36Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"180743065470998389126925578889115629695","length":2949},"id":"CVE-2026-103222-52a7273c","signature_type":"Function","signature_version":"v1","source":"https://github.com/blosc/c-blosc2/commit/fe2964d114d97847f56570a0ab2be2c57ccbeedc","target":{"file":"blosc/blosclz.c","function":"blosclz_compress"}},{"source":"https://github.com/blosc/c-blosc2/commit/fe2964d114d97847f56570a0ab2be2c57ccbeedc","target":{"file":"blosc/blosclz.c","function":"blosclz_decompress"},"deprecated":false,"digest":{"function_hash":"318627736217903749621540952255611696579","length":1750},"id":"CVE-2026-103222-72737437","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["83305595801173910135473303398343836853","99858171549699031524543291481269008692","310379337125174403726690294636732220768","306197382704615242970017806532969507908","71229939964044344900088030342632789843","289612841100890135653324972789607075777","287963379182232099262718820455176691795","65514011007372156324751906045363707145","239912656002100778306982409396551236565","170976759242816696797008747396797218686","298749185319559027944551863316038691260","323566714944527039803155540261879127340","162315598789009985798272651458776793467","54765097313853466484227684509490484160","312619108418847013621168178805609903195","195857810581996304780358975181374238749","307320676779526759820185688696825887870","38716660003349257664404447069034587345","155815535576988535929595657857423437753","4526677113252816590783024285968468683","95132121379681787688488072785823367422","269085670054730050339489550944663675816","208699448623453082961957876371596803265","63772881518831452641208109052754787541","282076576741870587540454096286841627213","315025737540500570061293310127561918777","207375076379076260003578720870313785838","299478473540109915991048099097637772874","44883374230620601260887321547701148048","1945045610160955526808028310580209244","107278564497043987512510398144105978969","23113544437091681953317422692879100733","195857810581996304780358975181374238749","307320676779526759820185688696825887870","49307747760757396524623905522872516562","288699849846348445915786279561463080580","301237289162234209561291969018791226713","312765035473963354968827124250007955497","175124885666503364211678306232006896445","102902842600749963865391570817268551971","146189119306091881309645447067726206608","113837827988212048937827426618305156668","140514291809637437137592112358894051883","281269720077732276676383048973841491404","177245918664717831296813998657773791334","297801913928440805922010250897393556527","147972448079317269646443736890286657178","84699150346379963426995809842515778136","310179900445484043320247818973354416096","67065168241878202802806391695454800217","254247848179859433937332598639586205817","79287194867805112490204067834747542078","215138783992046351830153893190472922023","109431317230862967685329094272300640494","29261211869952779992452199687281178147","44070743195639550291046143794348726794","251387744273294204654754361158298440506","99587771501433859670348163582944057543","334327658480828873268514889809165097454","84119322804726969607658855773475772970","7769167947591204034815928132917075367","237423324693938133002607262502976106308","204603208039492463289857565764429792403","198080133430819456497098878181759448896"],"threshold":0.9},"id":"CVE-2026-103222-c22c8029","signature_type":"Line","signature_version":"v1","source":"https://github.com/blosc/c-blosc2/commit/fe2964d114d97847f56570a0ab2be2c57ccbeedc","target":{"file":"blosc/blosclz.c"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}