CVE-2026-55209

9.8

Equinor · resdata

Equinor resdata versions prior to 6.2.9 contain multiple memory safety vulnerabilities, including buffer overflows, that occur when parsing malformed GRDECL files.

Executive summary

A critical buffer overflow vulnerability in Equinor resdata allows unauthenticated remote attackers to achieve arbitrary code execution or cause service termination.

Vulnerability

The software fails to properly validate numeric fields and grid dimensions when processing GRDECL files, leading to memory corruption issues such as classic buffer overflows, out-of-bounds reads, and NULL pointer dereferences. This vulnerability is exploitable by an unauthenticated remote attacker through the submission of specially crafted input files.

Business impact

The vulnerability carries a CVSS score of 9.8, reflecting its potential for total system compromise. Successful exploitation could lead to unauthorized remote code execution, enabling attackers to gain full control over the host system, access sensitive reservoir simulation data, or cause significant operational disruption by terminating critical services.

Remediation

Immediate Action: Upgrade to Equinor resdata version 6.2.9 or later immediately to apply the necessary input validation checks.

Proactive Monitoring: Monitor system logs for unexpected service crashes or anomalous memory usage patterns associated with the resdata parsing engine.

Compensating Controls: Restrict access to any network services that accept or process GRDECL files to trusted sources only, and implement strict file validation schemas where possible.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical severity of this vulnerability and the potential for unauthenticated remote code execution, organizations utilizing resdata must prioritize the update to version 6.2.9. Failure to remediate this flaw exposes infrastructure to significant risk of compromise, and immediate patching is the only effective method to eliminate the underlying memory safety issues.

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources