Out-of-bounds read in Raptor RDF Syntax Library - CVE-2024-57822

 

Out-of-bounds read in Raptor RDF Syntax Library - CVE-2024-57822

Published: November 12, 2025


Vulnerability identifier: #VU118386
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-57822
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal(). A remote attacker can perform a denial of service attack.


Affected software

Raptor RDF Syntax Library
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Desktop Applications Module
openSUSE Leap
Ubuntu
openEuler
raptor2 (Ubuntu package)
raptor2
raptor2-debuginfo
raptor2-debugsource
raptor2-devel
raptor2-help
raptor
libraptor-devel
libraptor2-0
raptor-debuginfo
raptor-debugsource
libraptor2-0-debuginfo
libraptor2-0-32bit-debuginfo
libraptor2-0-32bit

How to mitigate CVE-2024-57822

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

raptor2 (Ubuntu package) - addressed in versions 2.0.14-1ubuntu0.16.04.1+esm1, 2.0.14-1ubuntu0.18.04.1+esm1
raptor2 - update to 2.0.15-21
raptor2-debuginfo - update to 2.0.15-21
raptor2-debugsource - update to 2.0.15-21
raptor2-devel - update to 2.0.15-21
raptor2-help - update to 2.0.15-21
raptor - update to 2.0.15-150200.9.18.1
libraptor-devel - update to 2.0.15-150200.9.18.1
libraptor2-0 - update to 2.0.15-150200.9.18.1
raptor-debuginfo - update to 2.0.15-150200.9.18.1
raptor-debugsource - update to 2.0.15-150200.9.18.1
libraptor2-0-debuginfo - update to 2.0.15-150200.9.18.1
libraptor2-0-32bit-debuginfo - update to 2.0.15-150200.9.18.1
libraptor2-0-32bit - update to 2.0.15-150200.9.18.1

External References

Related Security Bulletins