
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-10305 is an out-of-bounds read vulnerability in Samsung's open-source rlottie library that allows overread of buffers, potentially enabling memory disclosure and application crashes. It affects all versions of rlottie prior to commit 223a2a41ba4f462e4abe767bebba49a366c9b9fd. The vulnerability was disclosed on June 4, 2026, with the fix merged into the Samsung/rlottie master branch on May 12, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Advisory, Github Advisory).
The root cause is classified as CWE-125 (Out-of-bounds Read), specifically triggered by a signed shift issue in the rlottie library's buffer handling code. The vulnerability is exploitable locally (attack vector: local) with low attack complexity, requiring no privileges but necessitating user interaction — for example, a user opening or processing a malicious Lottie animation file. The fix was introduced via GitHub Pull Request #587 ("fixed signed shift issue") by contributor mihashco, which corrected the improper signed shift operation that allowed reads beyond the intended buffer boundary (GitHub PR #587, Github Advisory).
Successful exploitation can cause the application using rlottie to crash (high availability impact) and may allow an attacker to read sensitive data from adjacent memory regions (low integrity impact; no direct confidentiality impact per CVSS scoring). The scope is limited to the affected component without privilege escalation or lateral movement potential. The primary risk is application instability and potential memory disclosure of data adjacent to the overread buffer (Red Hat Advisory, Github Advisory).
Update Samsung rlottie to the patched version at or after commit 223a2a41ba4f462e4abe767bebba49a366c9b9fd (merged May 12, 2026). Downstream consumers of rlottie — including applications and Linux distributions packaging the library — should update to a version incorporating this commit. As interim mitigations, implement input validation and bounds checking for buffer operations, and consider running rlottie in a sandboxed environment to limit the impact of any memory disclosure (GitHub PR #587, Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."