CVE-2023-39414
Description
Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix shift operation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer underflow when performing the right shift operation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Integer underflow in GTKWave 3.3.115 LXT2 parsing allows memory corruption via crafted .lxt2 file, requiring user interaction.
Vulnerability
The vulnerability resides in the LXT2 parsing functionality of GTKWave 3.3.115, specifically in the lxt2_rd_iter_radix shift operation where an integer underflow can occur. A specially crafted .lxt2 file can trigger this condition, leading to memory corruption. The code path is reachable when a victim opens a malicious .lxt2 file using GTKWave or its associated utilities.[1]
Exploitation
An attacker must craft a malicious .lxt2 file and convince a victim to open it, for example by double-clicking on the file or importing it into GTKWave. No authentication is required, but user interaction is necessary. The attacker does not need any special network position or privileges, as the vulnerability is triggered locally upon file opening.[1]
Impact
Successful exploitation results in memory corruption, which can potentially lead to arbitrary code execution, information disclosure, or denial of service. The CVSS v3.1 score is 7.0 (High) with impacts on confidentiality, integrity, and availability all rated as high.[1]
Mitigation
As of the publication date, no fix has been disclosed in the available references. Users are advised to avoid opening untrusted .lxt2 files and to monitor the vendor's website for updates. The only confirmed vulnerable version is GTKWave 3.3.115.[1]
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- GTKWave/GTKWavev5Range: 3.3.115
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.