Description
A vulnerability has been found in aardappel lobster up to 2025.4. Affected by this issue is the function lobster::Parser::ParseStatements in the library dev/src/lobster/parser.h of the component Parsing. The manipulation leads to memory corruption. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The identifier of the patch is 2f45fe860d00990e79e13250251c1dde633f1f89. Applying a patch is the recommended action to fix this issue.
Problem types
Product status
2025.1
2025.2
2025.3
2025.4
Timeline
| 2026-02-09: | Advisory disclosed |
| 2026-02-09: | VulDB entry created |
| 2026-02-18: | VulDB entry last update |
Credits
Oneafter (VulDB User)
References
vuldb.com/?id.345006 (VDB-345006 | aardappel lobster Parsing parser.h ParseStatements memory corruption)
vuldb.com/?ctiid.345006 (VDB-345006 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.753168 (Submit #753168 | aardappel lobster 8ba49f9 Memory Corruption)
github.com/aardappel/lobster/issues/396
github.com/aardappel/lobster/issues/396
github.com/oneafter/0204/blob/main/lob2/repro.lobster
github.com/...ommit/2f45fe860d00990e79e13250251c1dde633f1f89
github.com/aardappel/lobster/