← Back

CVE-2025-67873

nvd nist
Published: Dec 17, 2025Modified: Jan 2, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, Skipdata length is not bounds-checked, so a user-provided skipdata callback can make cs_disasm/cs_disasm_iter memcpy more than 24 bytes into cs_insn.bytes, causing a heap buffer overflow in the disassembly path. Commit cbef767ab33b82166d263895f24084b75b316df3 fixes the issue.

Affected (6)

Capstone
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Capstone Engine
Before 6.0.0
Version 6.0.0 alpha1
Version 6.0.0 alpha2
Version 6.0.0 alpha3
Version 6.0.0 alpha4
Version 6.0.0 alpha5

References (3)

Timeline

No history available yet.