Executive brief
Bitsery is a C++ library used by developers to convert complex data structures into a binary format for storage or transmission. A security flaw in how the library handles shared pointers allows an attacker to send specially crafted data that tricks the system into misidentifying data types. This can lead to sensitive information leaks, program crashes, or potentially allow an attacker to take control of the affected application.
Technical details
A type confusion vulnerability exists in Bitsery up to version 5.2.4 within the 'loadFromSharedState' function in 'include/bitsery/ext/std_smart_ptr.h'. The root cause is insufficient type validation during the deserialization of shared pointers; the library uses a shallow copy shortcut based on object IDs without verifying that the stored type matches the expected type. A remote attacker can provide a malicious serialized archive that forces a pointer of one type to reference an object of a different type. This can result in ASLR bypass via address leakage, arbitrary memory reads, VTable hijacking, or denial-of-service. The issue is fixed in version 5.2.5.
Affected products
- fraillt bitsery up to 5.2.4
Timeline
- 2025-10-09: patched: Version 5.2.5 released with fix
- 2026-05-26: advisory: NVD publication date
References
- https://gist.github.com/TrebledJ/750abc64a826f19dd2d6774724629b71
- https://github.com/fraillt/bitsery/
- https://github.com/fraillt/bitsery/blob/master/CHANGELOG.md
- https://github.com/fraillt/bitsery/commit/66d16516e24893bebc1c8af52bf2fe9ad0735061
- https://github.com/fraillt/bitsery/releases/tag/v5.2.5
- https://vuldb.com/submit/814457
- https://vuldb.com/vuln/365541