PT-2026-56196 · Django+1 · Django+1
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Django versions 6.0 through 6.0.6
Django versions 5.2 through 5.2.15
Description
An issue exists where
django.contrib.gis.gdal.GDALRaster over-reads its in-memory buffer when constructed from a bytes object. This can lead to the disclosure of adjacent memory or cause service degradation through a potential segmentation fault—a specific type of error that occurs when a program attempts to access a memory location it is not allowed to access—when the vsi buffer property is accessed.Recommendations
Update Django versions 6.0 through 6.0.6 to version 6.0.7.
Update Django versions 5.2 through 5.2.15 to version 5.2.16.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Django
Red Os