← Back

CVE-2026-47143

nvd nist
Published: Jul 21, 2026Modified: Jul 30, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`, allowing a remote attacker to crash any application using the reduced X86 Capstone library by supplying a crafted input containing the 4-byte sequence `0F 0F <modrm> <imm8>`. Versions 6.0.0-Alpha8 and 5.0.8 patch the issue.

Affected (8)

Capstone
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Capstone Engine
Before 5.0.8
Version 6.0.0 alpha1
Version 6.0.0 alpha2
Version 6.0.0 alpha3
Version 6.0.0 alpha4
Version 6.0.0 alpha5
Version 6.0.0 alpha6
Version 6.0.0 alpha7

References (5)

Source: security-advisories@github.com
Issue TrackingPatch
Source: security-advisories@github.com
ExploitVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitVendor Advisory

Timeline

No history available yet.