CVE-2026-49294: Padding Overread In Buffer Split
Calculating the width of the last element in a buffer by subtracting its offset from the total buffer size may cause out-of-bounds reads or information disclosure if the buffer includes trailing alignment padding. Verify if the size should be calculated directly based on the element's parsed structure rather than buffer bounds.
greprules fetch cve-2026-49294-padding-overread-in-buffer-split --engine opengrepDescription
Calculating the width of the last element in a buffer by subtracting its offset from the total buffer size may cause out-of-bounds reads or information disclosure if the buffer includes trailing alignment padding. Verify if the size should be calculated directly based on the element's parsed structure rather than buffer bounds.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.