PT-2026-83137 · Unknown · Codechecker

·

CVE-2026-58106

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v4.0

2.0

Low

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:P/S:N/AU:Y/R:U/RE:L/U:Green
Name of the Vulnerable Software and Affected Versions CodeChecker versions prior to 6.28.3
Description A stack overflow occurs during the invocation of the safe strcpy() helper function within the ldlogger-tool-gcc.c file. The issue arises because the function uses strncpy(), which NUL-pads the destination buffer to the full size of PATH MAX (4096 bytes). However, the destination pointer is offset by 2 bytes (fullPath + 2), leaving only 4094 bytes of available space. This results in a 2-byte overflow on every invocation, regardless of the input path length.
Recommendations Update to version 6.28.3 or later.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58106
GHSA-9GCG-V8FG-39Q8

Affected Products

Codechecker