CVE-2026-22891 PUBLISHED

Assigner: talos
Reserved: 28.01.2026 Published: 03.03.2026 Updated: 03.03.2026

A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor The Biosig Project
Product libbiosig
Versions
  • Version 3.9.2 is affected
  • Version Master Branch (db9a9a63) is affected

Credits

  • Discovered by Mark Bereza and Lilith >_> of Cisco Talos.

References

Problem Types

  • CWE-122: Heap-based Buffer Overflow CWE