Heap Buffer Over-read in ugrep Affects Data Processing Capabilities
CVE-2025-15614

4.8MEDIUM

Key Information:

Vendor

Genivia

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2025-15614?

The ugrep tool prior to version 7.6.0 is vulnerable to a heap buffer over-read when processing maliciously crafted .Z archive files. Attackers can exploit this vulnerability by supplying malformed files, which causes the decompressor to read beyond the allocated heap buffer, leading to potential application crashes. This issue was highlighted in GitHub Issue #511 and has been addressed in subsequent updates. Users are strongly advised to upgrade to version 7.6.0 or later to mitigate this risk.

Affected Version(s)

ugrep 0 < 7.6.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vlatko Kosturjak
.