Medium severity6.1NVD Advisory· Published Jun 10, 2026· Updated Jun 11, 2026
CVE-2026-49496
CVE-2026-49496
Description
Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator invalidation when PcodeCacher::allocateInstruction reallocates the issued vector. Attackers can trigger memory corruption by decompiling malicious binaries through the public Sleigh::oneInstruction C++ API, affecting downstream SLEIGH library consumers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 2 more
- (no CPE)
- cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:*range: <12.1
- (no CPE)range: <12.1
Patches
Vulnerability mechanics
References
3- github.com/NationalSecurityAgency/ghidra/commit/8a3018d5efcb07d2ec40bacdd6063cb6f01c8edfnvdPatch
- github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-gqh9-2c72-wpjcnvdExploitVendor Advisory
- www.vulncheck.com/advisories/ghidra-heap-use-after-free-in-sleighbuilder-generatepointeradd-via-vector-reallocationnvdThird Party Advisory
News mentions
1- National Security Agency's Ghidra: 15 Vulnerabilities Disclosed on June 10, 2026Vypr Intelligence · Jun 10, 2026