PT-2025-33721 · Libretro+1 · Retroarch+1

Simcha Kosman

+1

·

Published

2025-08-19

·

Updated

2025-09-12

·

CVE-2025-9136

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: libretro RetroArch versions 1.18.0 through 1.20.0
Description: A flaw has been found in the filestream vscanf function of the libretro-common/streams/file stream.c file. This manipulation causes an out-of-bounds read. The attack needs to be launched locally.
Recommendations: Upgrade to version 1.21.0 to mitigate this issue. Upgrade the affected component.

Exploit

Fix

Out of bounds Read

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-9136

Affected Products

Debian
Retroarch