Medium severity4.8OSV Advisory· Published Dec 17, 2025· Updated Jun 17, 2026
CVE-2025-68114
CVE-2025-68114
Description
Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a1618be12017d7d41e0b6581d5d529e fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
171.0, 2.0, 2.0-rc1, …+ 7 more
- (no CPE)range: 1.0, 2.0, 2.0-rc1, …
- cpe:2.3:a:capstone-engine:capstone:*:*:*:*:*:*:*:*range: <6.0.0
- cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha3:*:*:*:*:*:*
- cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha4:*:*:*:*:*:*
- cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha5:*:*:*:*:*:*
- (no CPE)range: <=6.0.0-Alpha5
- osv-coords9 versionspkg:rpm/almalinux/capstonepkg:rpm/almalinux/capstone-develpkg:rpm/almalinux/capstone-javapkg:rpm/almalinux/python3-capstonepkg:rpm/opensuse/capstone&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/capstone&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/capstone&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7pkg:rpm/suse/capstone&distro=SUSE%20Linux%20Micro%206.0pkg:rpm/suse/capstone&distro=SUSE%20Linux%20Micro%206.1
< 4.0.2-13.el9_8+ 8 more
- (no CPE)range: < 4.0.2-13.el9_8
- (no CPE)range: < 4.0.2-13.el9_8
- (no CPE)range: < 4.0.2-13.el9_8
- (no CPE)range: < 4.0.2-13.el9_8
- (no CPE)range: < 4.0.2-150500.3.3.1
- (no CPE)range: < 4.0.2-150500.3.3.1
- (no CPE)range: < 4.0.2-150500.3.3.1
- (no CPE)range: < 4.0.2-6.1
- (no CPE)range: < 4.0.2-slfo.1.1_2.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.