← Vulnerability feed

Vulnerability record · CVE-2025-50343 · published 30 December 2025

CVE-2025-50343: Matio project matio heap-based buffer overflow vulnerability

MMatio Project · Matio

An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the fields array. This leads to out-of-bounds reads and invalid memory frees during cleanup, potentially causing a segmentation fault or heap corruption.

9.8 CVSS 3.1 Critical EPSS 0.41% · top 67.2% CWE-122 · Heap-based buffer overflow
9.8CVSS 3.1 base score
0.41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the fields array. This leads to out-of-bounds reads and invalid memory frees during cleanup, potentially causing a segmentation fault or heap corruption.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/tbeu/matio/issues/275 ExploitIssue TrackingThird Party Advisory
https://github.com/zakkanijia/POC/blob/main/matio/CVE-2025-50343/matio.md ExploitThird Party Advisory
https://github.com/tbeu/matio/issues/275 ExploitIssue TrackingThird Party Advisory
https://github.com/zakkanijia/POC/blob/main/matio/CVE-2025-50343/matio.md ExploitThird Party Advisory

Track CVE-2025-50343 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-13107Matio project matio integer overflow vulnerabilityMultiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.cEPSS 1.8%9.1CVE-2019-9037Matio project matio out-of-bounds read vulnerabilityAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a buffer over-read in the function Mat_VarPrint() in mat.c.EPSS 2.3%9.1CVE-2019-9028Matio project matio out-of-bounds read vulnerabilityAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in the function InflateDime…EPSS 2.0%9.1CVE-2019-9030Matio project matio out-of-bounds read vulnerabilityAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in Mat_VarReadNextInfo5() i…EPSS 2.3%9.1CVE-2019-9033Matio project matio out-of-bounds read vulnerabilityAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read for the "Rank and Dimension…EPSS 2.1%9.1CVE-2019-9034Matio project matio out-of-bounds read vulnerabilityAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read for a memcpy in the functio…EPSS 2.0%9.1CVE-2019-9035Matio project matio out-of-bounds read vulnerabilityAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in the function ReadNextStr…EPSS 2.3%8.8CVE-2020-19497Matio project matio integer overflow vulnerabilityInteger overflow vulnerability in Mat_VarReadNextInfo5 in mat5.c in tbeu matio (aka MAT File I/O Library) 1.5.17, allows attackers to cause a Denial …EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2025-50343), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.