Vulnerability Details CVE-2025-68114
Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a1618be12017d7d41e0b6581d5d529e fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.9%
CVSS Severity
CVSS v3 Score 4.8
Products affected by CVE-2025-68114
-
cpe:2.3:a:capstone-engine:capstone:1.0
-
cpe:2.3:a:capstone-engine:capstone:2.0
-
cpe:2.3:a:capstone-engine:capstone:2.1
-
cpe:2.3:a:capstone-engine:capstone:2.1.1
-
cpe:2.3:a:capstone-engine:capstone:2.1.2
-
cpe:2.3:a:capstone-engine:capstone:3.0
-
cpe:2.3:a:capstone-engine:capstone:3.0.1
-
cpe:2.3:a:capstone-engine:capstone:3.0.2
-
cpe:2.3:a:capstone-engine:capstone:3.0.3
-
cpe:2.3:a:capstone-engine:capstone:3.0.4
-
cpe:2.3:a:capstone-engine:capstone:3.0.5
-
cpe:2.3:a:capstone-engine:capstone:4.0
-
cpe:2.3:a:capstone-engine:capstone:4.0.1
-
cpe:2.3:a:capstone-engine:capstone:4.0.2
-
cpe:2.3:a:capstone-engine:capstone:5.0
-
cpe:2.3:a:capstone-engine:capstone:5.0.1
-
cpe:2.3:a:capstone-engine:capstone:5.0.2
-
cpe:2.3:a:capstone-engine:capstone:5.0.3
-
cpe:2.3:a:capstone-engine:capstone:5.0.4
-
cpe:2.3:a:capstone-engine:capstone:5.0.5
-
cpe:2.3:a:capstone-engine:capstone:5.0.6
-
cpe:2.3:a:capstone-engine:capstone:6.0.0