Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
A vulnerability in Samsung Open Source rlottie allows memory allocation with an excessive size value, leading to excessive allocation. This affects specific rlottie versions prior to commit 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd. The issue can cause denial of service due to resource exhaustion but does not impact confidentiality or integrity.
AI Analysis
Technical Summary
The rlottie library contains a vulnerability where memory allocation requests can specify an excessively large size value, resulting in excessive memory allocation. This flaw affects rlottie versions before commit 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd, including several Ubuntu package versions. The vulnerability has a CVSS 3.1 vector indicating local attack vector, low attack complexity, no privileges required, user interaction required, unchanged scope, no confidentiality impact, low integrity impact, and high availability impact. This suggests the primary impact is denial of service via resource exhaustion.
Potential Impact
The vulnerability can lead to denial of service conditions by exhausting system memory through excessive allocation requests. There is no impact on confidentiality, and integrity impact is low. No known exploits have been reported in the wild, indicating limited current exploitation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor official rlottie and Ubuntu security advisories for patches addressing this issue. Until a patch is available, avoid processing untrusted input that could trigger excessive memory allocation in rlottie.
Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
Description
A vulnerability in Samsung Open Source rlottie allows memory allocation with an excessive size value, leading to excessive allocation. This affects specific rlottie versions prior to commit 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd. The issue can cause denial of service due to resource exhaustion but does not impact confidentiality or integrity.
CVSS v3.1
Affected software
pkg:deb/ubuntu/rlottie@0~git20200305.a717479+dfsg-1ubuntu0.1~esm3?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+dfsg-2ubuntu0.2+esm1?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]+dfsg-4ubuntu1.1+esm1?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]+dfsg-4.2ubuntu0.1?arch=source&distro=questingpkg:deb/ubuntu/[email protected]+dfsg-4.3ubuntu0.1~esm1?arch=source&distro=esm-apps/resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The rlottie library contains a vulnerability where memory allocation requests can specify an excessively large size value, resulting in excessive memory allocation. This flaw affects rlottie versions before commit 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd, including several Ubuntu package versions. The vulnerability has a CVSS 3.1 vector indicating local attack vector, low attack complexity, no privileges required, user interaction required, unchanged scope, no confidentiality impact, low integrity impact, and high availability impact. This suggests the primary impact is denial of service via resource exhaustion.
Potential Impact
The vulnerability can lead to denial of service conditions by exhausting system memory through excessive allocation requests. There is no impact on confidentiality, and integrity impact is low. No known exploits have been reported in the wild, indicating limited current exploitation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor official rlottie and Ubuntu security advisories for patches addressing this issue. Until a patch is available, avoid processing untrusted input that could trigger excessive memory allocation in rlottie.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-47319
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:Pro:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a5e7a762a4a8d59899ded1e
Added to database: 07/20/2026, 19:43:50 UTC
Last enriched: 07/20/2026, 20:57:43 UTC
Last updated: 07/21/2026, 08:42:50 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.