PYSEC-2026-1534

Vulnerability from pysec - Published: 2026-07-07 11:45 - Updated: 2026-07-07 11:45
VLAI
Details

Issue:

At ospd_common.c, on the osdp_reply_name function, any reply id between REPLY_ACK and REPLY_XRD is valid, but names array do not declare all of the range. On a case of an undefined reply id within the range, name will be null (name = names[reply_id - REPLY_ACK];). Null name will casue a crash on next line: if (name[0] == '\0') as null[0] is invalid.

Attack:

As this logic is not limited to a secure connection, attacker may trigger this vulnerability without any prior knowledge.

Impact

Denial of Service

Patch

The issue has been patched in 24409e98a260176765956ec766a04cb35984fab1

Impacted products
Name purl
libosdp pkg:pypi/libosdp

{
  "affected": [
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "libosdp",
        "purl": "pkg:pypi/libosdp"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.4.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2024-52296",
    "GHSA-7945-5mcv-f2pp"
  ],
  "details": "### Issue:\nAt ospd_common.c, on the osdp_reply_name function, any reply id between REPLY_ACK and REPLY_XRD is valid, but names array do not declare all of the range. On a case of an undefined reply id within the range, name will be null (`name = names[reply_id - REPLY_ACK];`). Null name will casue a crash on next line: `if (name[0] == \u0027\\0\u0027)` as null[0] is invalid.\n\n### Attack:\nAs this logic is not limited to a secure connection, attacker may trigger this vulnerability without any prior knowledge.\n\n### Impact\nDenial of Service\n\n### Patch\nThe issue has been patched in 24409e98a260176765956ec766a04cb35984fab1\n",
  "id": "PYSEC-2026-1534",
  "modified": "2026-07-07T11:45:34.729113Z",
  "published": "2026-07-07T11:45:34.729113Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/goToMain/libosdp/security/advisories/GHSA-7945-5mcv-f2pp"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52296"
    },
    {
      "type": "WEB",
      "url": "https://github.com/goToMain/libosdp/commit/24409e98a260176765956ec766a04cb35984fab1"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/goToMain/libosdp"
    },
    {
      "type": "PACKAGE",
      "url": "https://pypi.org/project/libosdp"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/advisories/GHSA-7945-5mcv-f2pp"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "LibOSDP vulnerable to a null pointer deref in osdp_reply_name"
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…