Executive brief
flatcc is a FlatBuffers compiler and C library used for serializing and deserializing data structures efficiently. A memory leak exists in the parser cleanup function where the keyword table is not deallocated, potentially causing memory to accumulate over time when processing multiple schema files. This can degrade performance or exhaust available memory in long-running compilation processes.
Technical details
The vulnerability is a memory leak in the fb_clear_parser function within src/compiler/parser.c. When the parser is cleared after processing a schema, the keyword_index table is not properly deallocated, only the include_index and attribute_index tables are freed. The fix adds a single call to fb_name_table_clear for the keyword_index. The vulnerability can be triggered remotely if the affected version is deployed as a compilation service, and requires no authentication. An attacker can repeatedly trigger schema compilation to accumulate memory leaks.
Affected products
- Dvidelabs flatcc up to 0.6.3
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Commit 8dbc3419738da066151991fd2bf1d0c85591dea2 addresses the issue