Buffer Overflow Vulnerability in Capstone Disassembly Framework
CVE-2025-68114

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 December 2025

What is CVE-2025-68114?

The Capstone Disassembly Framework has a buffer overflow vulnerability affecting versions 6.0.0-Alpha5 and earlier. The flaw is due to an unchecked vsnprintf return in the SStream_concat function, which can allow an attacker to manipulate the stream's index leading to potential stack buffer underflows or overflows. This condition occurs when subsequent writes are executed. The issue has been addressed in the latest commits, ensuring safer memory operations within the framework.

Affected Version(s)

capstone <= 6.0.0-Alpha5

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.