The utility functions used by Malwarebytes EDR 1.0.11 on Linux for calculating a cryptographic hash of data bytes truncate the hashed data if it exceeds 4GB. This leads to an integer wrap-around if the data is larger than the maximum unsigned integer value (32-bit). Attackers could create a colliding hash value for two different strings by attaching 4GB of data to a string that is less than 4GB in size.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.malwarebytes.com/secure/cves/cve-2023-29146 |
|
History
Tue, 09 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-190 | |
| Metrics |
cvssV3_1
|
Tue, 09 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The utility functions used by Malwarebytes EDR 1.0.11 on Linux for calculating a cryptographic hash of data bytes truncate the hashed data if it exceeds 4GB. This leads to an integer wrap-around if the data is larger than the maximum unsigned integer value (32-bit). Attackers could create a colliding hash value for two different strings by attaching 4GB of data to a string that is less than 4GB in size. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-09T19:25:28.255Z
Reserved: 2023-03-31T00:00:00.000Z
Link: CVE-2023-29146
Updated: 2026-06-09T19:25:11.070Z
Status : Deferred
Published: 2026-06-09T19:16:41.760
Modified: 2026-06-09T20:16:29.207
Link: CVE-2023-29146
No data.
OpenCVE Enrichment
No data.