Executive brief
Open Babel is a chemical toolbox designed to speak the many languages of chemical data. A memory management flaw was discovered in how it processes GAMESS output files, which could allow a local attacker to cause a program crash or potentially execute unauthorized code. This could impact the reliability of scientific data processing and the security of systems running the software.
Technical details
A use-after-free vulnerability exists in Open Babel versions prior to 3.2.0 within the GAMESSOutputFormat::ReadMolecule function in gamessformat.cpp. The issue arises during the tokenization of input lines where a pointer to a token is passed to atoi/strtol after the underlying memory has been freed or cleared by the tokenize function's internal operations. A local attacker can exploit this by providing a specially crafted GAMESS output file. Successful exploitation can lead to a denial of service (application crash) or potentially arbitrary code execution. The vulnerability is addressed in version 3.2.0.
Affected products
- Open Babel openbabel < 3.2.0
Timeline
- 2025-09-14: disclosed: Initial bug report and PoC provided on GitHub
- 2025-09-26: advisory: GitHub Advisory published
- 2026-06-30: patched: Version 3.2.0 released/confirmed as fix