uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 24 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0. | |
| Title | uuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided | |
| Weaknesses | CWE-787 CWE-823 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-24T18:09:24.744Z
Reserved: 2026-04-22T15:11:54.673Z
Link: CVE-2026-41907
No data.
Status : Received
Published: 2026-04-24T19:17:14.490
Modified: 2026-04-24T19:17:14.490
Link: CVE-2026-41907
No data.
OpenCVE Enrichment
No data.