Unrated severityOSV Advisory· Published Dec 17, 2025· Updated Dec 18, 2025
Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow
CVE-2025-68114
Description
Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a1618be12017d7d41e0b6581d5d529e fixes the issue.
Affected products
1- Range: 1.0, 2.0, 2.0-rc1, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/capstone-engine/capstone/commit/2c7797182a1618be12017d7d41e0b6581d5d529emitrex_refsource_MISC
- github.com/capstone-engine/capstone/security/advisories/GHSA-85f5-6xr3-q76rmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.