CVE detail
CVE-2025-70101
An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 filesystem image. The vulnerability occurs due to insufficient validation of extent header fields before performing a binary search over extent index entries, which can result in invalid pointer calculations and an out-of-bounds memory read during extent tree traversal.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 8.0 · KEV 0.0 · OTX 0.0 · PoC 9.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- http://www.openwall.com/lists/oss-security/2026/06/29/6www.openwall.com
No excerpt available.
Exploitwww.openwall.comJun 3, 2026, 2:16 PM - https://infosec.exchange/@sigdevel/116668958927817708infosec.exchange
No excerpt available.
Exploitinfosec.exchangeJun 3, 2026, 2:16 PM No excerpt available.
Exploitgithub.comJun 3, 2026, 2:16 PMNo excerpt available.
Exploitgithub.comJun 3, 2026, 2:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
2 repository references · best confidence 0.90 · max 0 stars
- sigdevel/pocsHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 22, 2026, 9:11 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
- gkostka/lwext4High confidencegithubNVD Exploit reference0 starsDiscovered Jul 22, 2026, 9:11 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-66759CVSS 7.1 · High
A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if t…
- CVE-2026-66731CVSS 8.7 · High
facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the…
- CVE-2026-66729CVSS 8.7 · High
facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process…
- CVE-2026-17572CVSS 5.5 · Medium
Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted H…
- CVE-2026-15003CVSS 5.6 · Medium
A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-…
- CVE-2026-17512CVSS 1.9 · Low
A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the file src/whisper.cpp. The manipulation leads to out-of-bounds…