CVE-2026-55209: CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in equinor resdata
resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword sizes, and array indexes while parsing untrusted GRDECL files in lib/resdata/rd_kw_grdecl.cpp and lib/resdata/rd_grid.cpp. Malformed COORD, ZCORN, CORSNUM, ACTNUM, or MAPAXES data can reach rd_grid_alloc_GRDECL_kw__ with inconsistent lengths, while unbounded floating-point conversion can exceed the intended parser buffer. In a network service that accepts untrusted GRDECL files, these conditions can cause a classic buffer overflow, out-of-bounds reads, invalid array access, NULL pointer dereference, memory corruption, or service termination. This issue is fixed in version 6.2.9.
AI Analysis
Technical Summary
CVE-2026-55209 is a classic buffer overflow vulnerability (CWE-120) in Equinor's resdata software used for reading and writing Eclipse reservoir simulator result files. Versions before 6.2.9 do not adequately validate numeric fields, grid dimensions, keyword sizes, and array indexes during parsing of untrusted GRDECL files, specifically in the source files lib/resdata/rd_kw_grdecl.cpp and lib/resdata/rd_grid.cpp. Malformed data in COORD, ZCORN, CORSNUM, ACTNUM, or MAPAXES can cause inconsistent lengths and unbounded floating-point conversions that exceed parser buffer limits. When exploited in a network service accepting untrusted GRDECL files, this can cause buffer overflows, out-of-bounds reads, invalid array accesses, NULL pointer dereferences, memory corruption, or service crashes. The vulnerability is resolved in version 6.2.9.
Potential Impact
Successful exploitation can lead to remote code execution, denial of service, or memory corruption due to buffer overflow and related memory errors. The CVSS 3.1 score of 9.8 reflects critical impact with network attack vector, no privileges required, and no user interaction needed. Confidentiality, integrity, and availability are all highly impacted.
Mitigation Recommendations
Upgrade to resdata version 6.2.9 or later, where this vulnerability is fixed. No other mitigations are specified. Patch status is confirmed fixed in 6.2.9.
CVE-2026-55209: CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in equinor resdata
Description
resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword sizes, and array indexes while parsing untrusted GRDECL files in lib/resdata/rd_kw_grdecl.cpp and lib/resdata/rd_grid.cpp. Malformed COORD, ZCORN, CORSNUM, ACTNUM, or MAPAXES data can reach rd_grid_alloc_GRDECL_kw__ with inconsistent lengths, while unbounded floating-point conversion can exceed the intended parser buffer. In a network service that accepts untrusted GRDECL files, these conditions can cause a classic buffer overflow, out-of-bounds reads, invalid array access, NULL pointer dereference, memory corruption, or service termination. This issue is fixed in version 6.2.9.
CVSS v3.1
Score 9.8critical
Affected software
equinor
resdata
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-55209 is a classic buffer overflow vulnerability (CWE-120) in Equinor's resdata software used for reading and writing Eclipse reservoir simulator result files. Versions before 6.2.9 do not adequately validate numeric fields, grid dimensions, keyword sizes, and array indexes during parsing of untrusted GRDECL files, specifically in the source files lib/resdata/rd_kw_grdecl.cpp and lib/resdata/rd_grid.cpp. Malformed data in COORD, ZCORN, CORSNUM, ACTNUM, or MAPAXES can cause inconsistent lengths and unbounded floating-point conversions that exceed parser buffer limits. When exploited in a network service accepting untrusted GRDECL files, this can cause buffer overflows, out-of-bounds reads, invalid array accesses, NULL pointer dereferences, memory corruption, or service crashes. The vulnerability is resolved in version 6.2.9.
Potential Impact
Successful exploitation can lead to remote code execution, denial of service, or memory corruption due to buffer overflow and related memory errors. The CVSS 3.1 score of 9.8 reflects critical impact with network attack vector, no privileges required, and no user interaction needed. Confidentiality, integrity, and availability are all highly impacted.
Mitigation Recommendations
Upgrade to resdata version 6.2.9 or later, where this vulnerability is fixed. No other mitigations are specified. Patch status is confirmed fixed in 6.2.9.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-16T16:16:32.627Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa852d455bf5e2cf5892f90
Added to database: 09/14/2026, 20:02:28 UTC
Last enriched: 09/14/2026, 20:17:06 UTC
Last updated: 09/15/2026, 08:56:27 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.