Executive brief
Open Babel, a chemical toolbox used to search, convert, and analyze chemical data, is vulnerable to a memory corruption flaw. An attacker with local access to a system could provide a specially crafted chemical data file to trigger a crash or potentially execute unauthorized code. This could lead to a loss of data confidentiality, integrity, or system availability.
Technical details
A heap-based buffer overflow exists in Open Babel versions prior to 3.2.0 within the ChemKinFormat::CheckSpecies function in /src/formats/chemkinformat.cpp. The vulnerability is triggered when the library processes malformed ChemKin format input files, where an unchecked or malformed string is used as a lookup key in a std::map::find call, leading to an out-of-bounds read/write. An attacker with local access can exploit this by providing a crafted file to a tool using the Open Babel library (e.g., fuzz_convert). While NVD and VulDB provide varying CVSS scores, the NVD assessment indicates a high severity (7.8) due to potential impacts on confidentiality, integrity, and availability. The issue is addressed in version 3.2.0.
Affected products
- Open Babel openbabel < 3.2.0
Timeline
- 2025-09-14: disclosed: Initial bug report on GitHub issue tracker
- 2025-09-26: advisory: GitHub and NVD advisories published
- 2026-07-01: patched: Advisory updated to reflect fix in version 3.2.0