The argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, then argon2i_32 will write past the end of the buffer and possibly corrupt the heap.
Fixed in 4.0.2.8, which now verifies that nb_blocks is large enough. See 90ff5b1.
Provide a correctly sized nb_blocks buffer.
pymonocypher thanks Haris (hextheshadow) for the vulnerability report, details, and recommended fix.
0.1.10.1.20.1.30.1.43.1.0.03.1.3.03.1.3.13.1.3.23.1.3.33.1.3.4+9 more4.0.2.8Exploitability
AV:LAC:LAT:NPR:NUI:NVulnerable System
VC:NVI:LVA:LSubsequent System
SC:NSI:NSA:NCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N