#VU56239 Stack-based buffer overflow in hivex - CVE-2021-3622
Published: September 1, 2021
hivex
libguestfs
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing hive child objects. A local user can create a specially crafted Windows Registry (hive) file which would cause hivex to recursively call the _get_children() function, ultimately leading to a stack overflow and library crash.