Description
An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the fields array. This leads to out-of-bounds reads and invalid memory frees during cleanup, potentially causing a segmentation fault or heap corruption.
References
https://github.com/tbeu/matio/issues/275
https://github.com/zakkanijia/POC/blob/main/matio/CVE-2025-50343/matio.md
https://github.com/tbeu/matio/issues/275
https://github.com/zakkanijia/POC/blob/main/matio/CVE-2025-50343/matio.md
Weaknesses
134c704f-9b21-4f2e-91b3-4a467353bcc0
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 · Critical
Information
Source identifier
Vulnerability status
Analyzed
Published
2025-12-30T20:16:00.217Z
2 weeks agoLast modified
2026-01-09T19:38:18.740Z
1 week ago