There is a use-after-free vulnerability in sentry!sentry_span_set_data() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions
History

Thu, 18 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 15:00:00 +0000

Type Values Removed Values Added
Description There is a use-after-free vulnerability in sentry!sentry_span_set_data() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions
Title Use-after-Free in sentry!sentry_span_set_data() in NI LabVIEW
First Time appeared Ni
Ni labview
Weaknesses CWE-416
CPEs cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:*
Vendors & Products Ni
Ni labview
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2025-12-18T15:02:41.277Z

Reserved: 2025-11-04T16:05:53.433Z

Link: CVE-2025-64468

cve-icon Vulnrichment

Updated: 2025-12-18T15:02:33.376Z

cve-icon NVD

Status : Received

Published: 2025-12-18T15:15:59.043

Modified: 2025-12-18T15:15:59.043

Link: CVE-2025-64468

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.