PT-2026-48419 · Ghidra · Ghidra
CVSS v4.0
6.7
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ghidra versions prior to 12.1.1
Description
The Mach-O binary parser contains an uncontrolled memory allocation issue that can lead to a denial of service. An attacker can provide a specially crafted Mach-O binary with an arbitrarily large
ncmds load command count value. This forces the parser to allocate excessive heap memory without validating the file size, resulting in a crash of the Ghidra JVM (Java Virtual Machine).Recommendations
Update to version 12.1.1 or later.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghidra