PT-2025-28832 · 9Fans · Plan9Port

Jjleo

·

Published

2025-07-09

·

Updated

2026-02-02

·

CVE-2025-7209

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: 9fans plan9port versions prior to 9da5b44
Description: A vulnerability exists in the value decode function within the src/libsec/port/x509.c library. The manipulation of this function leads to a null pointer dereference. Local access is required for exploitation. The exploit has been publicly disclosed and may be used.
Recommendations: Apply the patch with identifier deae8939583d83fd798fca97665e0e94656c3ee8 to resolve this issue.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-7209

Affected Products

Plan9Port