CVE-2025-68114CRITICAL 9.8EPSS p3.9%

CVE-2025-68114CVE-2025-68114

Description

Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a1618be12017d7d41e0b6581d5d529e fixes the issue.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.14% probability of exploitation · percentile 3.9% · 2026-06-19T12:03:05Z
Published2025-12-17
Last modified2026-01-02

Underlying weaknesses· 2

CWE-120CWE-124

References

  1. https://github.com/capstone-engine/capstone/commit/2c7797182a1618be12017d7d41e0b6581d5d529e
  2. https://github.com/capstone-engine/capstone/security/advisories/GHSA-85f5-6xr3-q76r
  3. https://github.com/capstone-engine/capstone/security/advisories/GHSA-85f5-6xr3-q76r

2

TypeTargetConfidenceTier
WeaknessBuffer Copy without Checking Size of Input ('Classic Buffer Overflow')cwe-1200%live
WeaknessBuffer Underwrite ('Buffer Underflow')cwe-1240%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-6141
CVE
CVE-2025-34468
CVE
CVE-2025-69720
CVE
CVE-2025-22467
CVE
CVE-2025-10451
CVE
CVE-2025-41426
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.