Permalink
CVE-2026-2644
3.3 LOW
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
Activity log
- Created suggestion
niklasso minisat DIMACS File SolverTypes.h value out-of-bounds
A weakness has been identified in niklasso minisat up to 2.2.0. This issue affects the function Solver::value in the library core/SolverTypes.h of the component DIMACS File Parser. This manipulation of the argument variable index with the input 2147483648 causes out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
References
-
VDB-346406 | niklasso minisat DIMACS File SolverTypes.h value out-of-bounds vdb-entrytechnical-description
-
-
Submit #752775 | niklasso minisat master-branch Heap-based Buffer Overflow third-party-advisory
-
https://github.com/niklasso/minisat/issues/55 issue-tracking
-
Affected products
minisat
- ==2.0
- ==2.1
- ==2.2.0
Matching in nixpkgs
pkgs.minisat
Compact and readable SAT solver
pkgs.cryptominisat
Advanced SAT Solver
pkgs.ocamlPackages.minisat
Simple bindings to Minisat-C
pkgs.haskellPackages.minisat
A Haskell bundle of the Minisat SAT solver
pkgs.ocamlPackages_latest.minisat
Simple bindings to Minisat-C
pkgs.haskellPackages.minisat-solver
High-level Haskell bindings for the MiniSat SAT solver
pkgs.sbclPackages.cl-sat_dot_minisat
None
-
nixos-unstable 20241012-git
- nixpkgs-unstable 20241012-git
- nixos-unstable-small 20241012-git
-
nixos-25.11 20241012-git
- nixos-25.11-small 20241012-git
- nixpkgs-25.11-darwin 20241012-git
Package maintainers
-
@Mic92 Jörg Thalheim <joerg@thalheim.io>
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>
-
@Uthar Kasper Gałkowski <galkowskikasper@gmail.com>
-
@hraban Hraban Luyat <hraban@0brg.net>
-
@lukego Luke Gorrie <luke@snabb.co>
-
@nagy Daniel Nagy <danielnagy@posteo.de>
-
@mgttlinger Merlin Humml <megoettlinger@gmail.com>