CVE-2025-54484
CRITICALlibbiosig < 3.9.1 - Stack-based Buffer Overflow in MFER Parsing
Title source: llmDescription
A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability manifests on line 8779 of biosig.c on the current master branch (35a819fa), when the Tag is 6: else if (tag==6) // 0x06 "number of sequences" { // NRec if (len>4) fprintf(stderr,"Warning MFER tag6 incorrect length %i>4\n",len); curPos += ifread(buf,1,len,hdr);
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://talosintelligence.com/vulnerability_reports/TALOS-2025-2234
Third Party Advisory
https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2234
Scores
CVSS v3
9.8
EPSS
0.0064
EPSS Percentile
45.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-121
Status
published
Products (1)
libbiosig_project/libbiosig
< 3.9.1
Published
Aug 25, 2025
Tracked Since
Feb 18, 2026