PT-2026-57824 · Storable+2 · Storable+2

CVE-2026-57433

·

Published

2026-07-13

·

Updated

2026-09-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Storable versions prior to 3.41
Description A signed integer overflow occurs during the deserialization of a specially crafted SX HOOK record. The function retrieve hook common() reads a signed 32-bit item count and passes it to av extend() after adding one. If the count is set to I32 MAX, the addition wraps to a negative value. When a crafted blob is processed by thaw() or retrieve(), this overflow causes av extend() to receive a negative count, resulting in a panic that terminates the deserialization process.
Recommendations Update to version 3.41 or later.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92415
CVE-2026-57433
ECHO-D227-33D7-30BD
OESA-2026-3224
USN-8675-1
USN-8675-2
USN-8684-1

Affected Products

Linuxmint
Storable
Ubuntu