Use After Free Vulnerability in Ghidra Software by National Security Agency
CVE-2024-58350

2.1LOW

Key Information:

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2024-58350?

Ghidra, prior to version 11.2, exposes a use after free vulnerability within the Sleigh backend, stemming from the improper initialization order of key singleton components. This flaw may allow attackers to provoke a denial of service condition or an infinite loop during the shutdown sequence, as it inadvertently references deallocated memory. Proper management of the static initialization order is crucial to mitigate this potential exploitation risk.

Affected Version(s)

ghidra 0 < 11.2

ghidra 11.2

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bill Bierman (@wbierman)
.