Severity: moderate 

Affected versions:

- Apache DataSketches 4.1.0 through 5.2.0

Description:

Out-of-bounds read and write in the Count-Min sketch deserialization of Apache 
DataSketches C++ (repo: datasketches-cpp).

count_min_sketch::deserialize() did not include the preamble in its input size 
check, so a truncated sketch could cause a read of up to 16 bytes past the end 
of the input. In addition, the table size was computed from the serialized 
number of buckets and number of hash functions in 32-bit arithmetic. A crafted 
sketch could make it wrap to zero, so that the sketch deserialized with an 
empty table, and later updates and estimate queries read and wrote outside the 
heap allocation. This can corrupt heap memory, causing a crash and potentially 
enabling further exploitation.

This issue affects Apache DataSketches C++: from 4.1.0 before 5.3.0. Only 
applications that deserialize Count-Min sketches from untrusted sources are 
affected.

Users are recommended to upgrade to version 5.3.0, which fixes this issue.

Credit:

He Huang (finder)
NexusSan (tool)

References:

https://datasketches.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-103634

Reply via email to