Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a1618be12017d7d41e0b6581d5d529e fixes the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a1618be12017d7d41e0b6581d5d529e fixes the issue. | |
| Title | Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow | |
| Weaknesses | CWE-120 CWE-124 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-17T21:14:31.226Z
Reserved: 2025-12-15T16:16:22.744Z
Link: CVE-2025-68114
No data.
Status : Received
Published: 2025-12-17T22:16:01.400
Modified: 2025-12-17T22:16:01.400
Link: CVE-2025-68114
No data.
OpenCVE Enrichment
No data.