High severity7.8NVD Advisory· Published Nov 27, 2020· Updated Jun 17, 2026
CVE-2020-29367
CVE-2020-29367
Description
blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
blosc2PyPI | < 0.1.7 | 0.1.7 |
Affected products
15- Blosc/C-Blosc2description
- ghsa-coords5 versionspkg:pypi/blosc2pkg:rpm/opensuse/blosc&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/blosc&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/opensuse/blosc&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/blosc&distro=SUSE%20Package%20Hub%2015%20SP2
< 0.1.7+ 4 more
- (no CPE)range: < 0.1.7
- (no CPE)range: < 1.20.1-bp152.4.3.1
- (no CPE)range: < 1.20.1-bp152.4.3.1
- (no CPE)range: < 1.20.1-bp152.4.3.1
- (no CPE)range: < 1.20.1-bp152.4.3.1
cpe:2.3:a:blosc:c-blosc2:2.0.0:alpha2:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:blosc:c-blosc2:2.0.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:blosc:c-blosc2:2.0.0:alpha3:*:*:*:*:*:*
- cpe:2.3:a:blosc:c-blosc2:2.0.0:alpha4:*:*:*:*:*:*
- cpe:2.3:a:blosc:c-blosc2:2.0.0:alpha5:*:*:*:*:*:*
- cpe:2.3:a:blosc:c-blosc2:2.0.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:blosc:c-blosc2:2.0.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:blosc:c-blosc2:2.0.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:blosc:c-blosc2:2.0.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:blosc:c-blosc2:2.0.0:beta5:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- github.com/Blosc/c-blosc2/commit/c4c6470e88210afc95262c8b9fcc27e30ca043eenvdPatchThird Party AdvisoryWEB
- bugs.chromium.org/p/oss-fuzz/issues/detailnvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-8c7c-2c8j-3xfpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-29367ghsaADVISORY
- github.com/Blosc/python-blosc2/releases/tag/v0.1.7ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/blosc2/PYSEC-2020-343.yamlghsaWEB
News mentions
0No linked articles in our index yet.