PT-2026-97124 · Ghidra · Ghidra
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ghidra versions prior to 12.1.4
Description
The software fails to validate the
TYPE COL byte within the createUnregisteredOption() function of the OptionsDB class. This lack of validation can lead to an ArrayIndexOutOfBoundsException, which results in domain objects becoming permanently locked. A remote actor can exploit this by crafting a malicious program database file that, upon import, causes the application to stall and prevents the graceful shutdown of the system or the cleanup of resources.Recommendations
Update to version 12.1.4 or later.
Exploit
Fix
DoS
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ghidra