PT-2026-48413 · Ghidra · Ghidra
CVSS v4.0
6.7
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ghidra versions prior to 12.0.3
Description
An out-of-memory issue exists in the
rust demangle() function, which allocates unbounded output buffers without size limits. This allows attackers to craft malicious Rust symbol names within binaries to trigger exponential memory allocation, leading to process crashes during binary analysis.Recommendations
Update to version 12.0.3 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghidra