Heap buffer overflow in the HLL sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp).
When deserializing a sketch in LIST mode, from either a byte buffer or a stream, the coupon count was read from the input and used as the number of entries to copy into a fixed buffer of 8 entries, without checking it against the buffer's capacity. A crafted sketch could cause a write of up to 988 bytes past the end of this internal heap buffer. This can corrupt heap memory, causing a crash and potentially enabling further exploitation.
This issue affects Apache DataSketches C++: from 1.0.0-incubating before 5.3.0. Only applications that deserialize HLL sketches from untrusted sources are affected.
Users are recommended to upgrade to version 5.3.0, which fixes this issue.
When deserializing a sketch in LIST mode, from either a byte buffer or a stream, the coupon count was read from the input and used as the number of entries to copy into a fixed buffer of 8 entries, without checking it against the buffer's capacity. A crafted sketch could cause a write of up to 988 bytes past the end of this internal heap buffer. This can corrupt heap memory, causing a crash and potentially enabling further exploitation.
This issue affects Apache DataSketches C++: from 1.0.0-incubating before 5.3.0. Only applications that deserialize HLL sketches from untrusted sources are affected.
Users are recommended to upgrade to version 5.3.0, which fixes this issue.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 10 Oct 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Heap buffer overflow in the HLL sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). When deserializing a sketch in LIST mode, from either a byte buffer or a stream, the coupon count was read from the input and used as the number of entries to copy into a fixed buffer of 8 entries, without checking it against the buffer's capacity. A crafted sketch could cause a write of up to 988 bytes past the end of this internal heap buffer. This can corrupt heap memory, causing a crash and potentially enabling further exploitation. This issue affects Apache DataSketches C++: from 1.0.0-incubating before 5.3.0. Only applications that deserialize HLL sketches from untrusted sources are affected. Users are recommended to upgrade to version 5.3.0, which fixes this issue. | |
| Title | Apache DataSketches: datasketches-cpp: HLL CouponList Deserialization Buffer Overflow allows memory corruption via a crafted sketch | |
| Weaknesses | CWE-122 CWE-1284 |
|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-10T10:22:55.843Z
Reserved: 2026-09-30T17:29:03.761Z
Link: CVE-2026-103501
No data.
Status : Received
Published: 2026-10-10T11:17:34.853
Modified: 2026-10-10T11:17:34.853
Link: CVE-2026-103501
No data.
OpenCVE Enrichment
Updated: 2026-10-10T11:30:19Z