CVE-2023-37187: Blosc C-BLOSC2
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the zfp/blosc2-zfp.c zfp_acc_decompress. function.
Affected products
- Blosc C-BLOSC2: before 2.9.3 (fixed in 2.9.3)
Published 2023-12-25. Last modified 2026-06-17.