PT-2025-51920 · Capstone+1 · Capstone+1
Finder16
·
Published
2025-12-17
·
Updated
2026-03-25
·
CVE-2025-67873
CVSS v3.1
7.8
High
| AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Capstone versions 6.0.0-Alpha5 and prior
Description
Capstone, a disassembly framework, contains a flaw where the length of skipdata is not properly validated. A user-provided skipdata callback can trigger a heap buffer overflow in the disassembly path by allowing
cs disasm/cs disasm iter to write beyond the allocated memory in cs insn.bytes, specifically exceeding 24 bytes. This occurs due to insufficient bounds checking.Recommendations
Update to a version later than 6.0.0-Alpha5.
Exploit
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Capstone
Debian