Use After Free Vulnerability in Ghidra Software by National Security Agency
CVE-2024-58350
2.1LOW
What is CVE-2024-58350?
Ghidra, prior to version 11.2, exposes a use after free vulnerability within the Sleigh backend, stemming from the improper initialization order of key singleton components. This flaw may allow attackers to provoke a denial of service condition or an infinite loop during the shutdown sequence, as it inadvertently references deallocated memory. Proper management of the static initialization order is crucial to mitigate this potential exploitation risk.
Affected Version(s)
ghidra 0 < 11.2
ghidra 11.2
