Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade graphite2Upgrade graphite2-debuginfoUpgrade graphite2-devel | Jun 23, 2026 | Jun 23, 2026 |
| Amazon_linux_2023 | — | Upgrade graphite2Upgrade graphite2-debuginfoUpgrade graphite2-develUpgrade graphite2-debugsource | Jun 23, 2026 | Jun 5, 2026 |
| Debian | — | Upgrade graphite2 | Jul 12, 2026 | Jul 12, 2026 |
| Ubuntu | — | Upgrade libgraphite2-3Upgrade libreoffice | Jun 17, 2026 | Jun 5, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub