VYPR
Low severity2.9NVD Advisory· Published Jun 10, 2026· Updated Jun 11, 2026

CVE-2024-58350

CVE-2024-58350

Description

Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and XmlArchitectureCapability singletons. Attackers can trigger an infinite loop or denial of service during shutdown by exploiting the unsafe destruction order that causes iteration over deallocated memory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:*range: <11.2
    • (no CPE)range: <11.2

Patches

Vulnerability mechanics

References

2

News mentions

1