Junglewise Threat Intelligence

Open Babel use-after-free in GAMESSOutputFormat::ReadMolecule

Severity: medium · CVSS 5.3 · Published 2025-09-26

Technologies: Open Babel Openbabel. Vendors: PyPI.

Executive brief

Open Babel is a chemical toolbox designed to speak the many languages of chemical data. A memory management flaw was discovered in how it processes GAMESS output files, which could allow a local attacker to cause a program crash or potentially execute unauthorized code. This could impact the reliability of scientific data processing and the security of systems running the software.

Technical details

A use-after-free vulnerability exists in Open Babel versions prior to 3.2.0 within the GAMESSOutputFormat::ReadMolecule function in gamessformat.cpp. The issue arises during the tokenization of input lines where a pointer to a token is passed to atoi/strtol after the underlying memory has been freed or cleared by the tokenize function's internal operations. A local attacker can exploit this by providing a specially crafted GAMESS output file. Successful exploitation can lead to a denial of service (application crash) or potentially arbitrary code execution. The vulnerability is addressed in version 3.2.0.

Affected products

  • Open Babel openbabel < 3.2.0

Timeline

  • 2025-09-14: disclosed: Initial bug report and PoC provided on GitHub
  • 2025-09-26: advisory: GitHub Advisory published
  • 2026-06-30: patched: Version 3.2.0 released/confirmed as fix

References

Related threats