CVE-2023-37188: Blosc C-BLOSC2
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_rate_decompress at zfp/blosc2-zfp.c.
Affected products
- Blosc C-BLOSC2: before 2.9.3 (fixed in 2.9.3)
Published 2023-12-25. Last modified 2026-06-17.