Integer overflow in the ordered_malloc function in boost/pool/pool.hpp in Boost Pool before 3.9 makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large memory chunk size value, which causes less memory to be allocated than expected.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade boostUpgrade boost-docUpgrade boost-devel | Dec 1, 2016 | Jul 25, 2012 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 15, 2015 |
| Gentoo Linux | — | Upgrade dev-libs/boost. | May 28, 2021 | Jul 25, 2012 |
| Oracle_linux | — | Upgrade boost-openmpi-pythonUpgrade boost-graph-openmpiUpgrade boost-mpich2-develUpgrade boost-waveUpgrade boost-systemUpgrade boost-staticUpgrade boost-graphUpgrade boost-iostreamsUpgrade boost-pythonUpgrade boost-serializationUpgrade boost-mpich2-pythonUpgrade boost-docUpgrade boost-openmpi-develUpgrade boost-develUpgrade boost-date-timeUpgrade boost-mathUpgrade boost-filesystemUpgrade boost-openmpiUpgrade boost-program-optionsUpgrade boost-graph-mpich2Upgrade boost-threadUpgrade boostUpgrade boost-testUpgrade boost-mpich2Upgrade boost-regexUpgrade boost-signals | Oct 16, 2024 | Jul 25, 2012 |
| Suse | — | Upgrade boost-docUpgrade boost-develUpgrade boost-32bitUpgrade boost-devel-64bitUpgrade boost-64bitUpgrade boost | Dec 12, 2013 | Jul 25, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub