CVE-2026-22891

Critical
|9.8
Exploit Available

Plain English Summary

AI-powered analysis for quick understanding

An attacker can execute arbitrary code on a system by tricking a user into opening a specially crafted Intan CLP file using the vulnerable version of the libbiosig library. This vulnerability requires the attacker to deliver the malicious file to the target, making it essential for users to be cautious about the files they open.

Technical Description

A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References