CVE-2025-68114
EUVD-2025-20399517.12.2025, 22:16
Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a1618be12017d7d41e0b6581d5d529e fixes the issue.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| capstone-engine | capstone | 𝑥 < 6.0.0 |
| capstone-engine | capstone | 6.0.0:alpha1 |
| capstone-engine | capstone | 6.0.0:alpha2 |
| capstone-engine | capstone | 6.0.0:alpha3 |
| capstone-engine | capstone | 6.0.0:alpha4 |
| capstone-engine | capstone | 6.0.0:alpha5 |
𝑥
= Vulnerable software versions
Ubuntu Releases