CVE-2026-10305
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-10305 is an out-of-bounds read vulnerability in Samsung's open-source rlottie library that allows overread of buffers, potentially enabling memory disclosure and application crashes. It affects all versions of rlottie prior to commit 223a2a41ba4f462e4abe767bebba49a366c9b9fd. The vulnerability was disclosed on June 4, 2026, with the fix merged into the Samsung/rlottie master branch on May 12, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Advisory, Github Advisory).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read), specifically triggered by a signed shift issue in the rlottie library's buffer handling code. The vulnerability is exploitable locally (attack vector: local) with low attack complexity, requiring no privileges but necessitating user interaction — for example, a user opening or processing a malicious Lottie animation file. The fix was introduced via GitHub Pull Request #587 ("fixed signed shift issue") by contributor mihashco, which corrected the improper signed shift operation that allowed reads beyond the intended buffer boundary (GitHub PR #587, Github Advisory).

Impact

Successful exploitation can cause the application using rlottie to crash (high availability impact) and may allow an attacker to read sensitive data from adjacent memory regions (low integrity impact; no direct confidentiality impact per CVSS scoring). The scope is limited to the affected component without privilege escalation or lateral movement potential. The primary risk is application instability and potential memory disclosure of data adjacent to the overread buffer (Red Hat Advisory, Github Advisory).

Mitigation and workarounds

Update Samsung rlottie to the patched version at or after commit 223a2a41ba4f462e4abe767bebba49a366c9b9fd (merged May 12, 2026). Downstream consumers of rlottie — including applications and Linux distributions packaging the library — should update to a version incorporating this commit. As interim mitigations, implement input validation and bounds checking for buffer operations, and consider running rlottie in a sandboxed environment to limit the impact of any memory disclosure (GitHub PR #587, Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64529NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesJul 25, 2026
CVE-2026-64528NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesJul 25, 2026
CVE-2026-64527NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesJul 25, 2026
CVE-2026-64526NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesJul 25, 2026
CVE-2026-64525NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesJul 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management