Heap Use-After-Free Vulnerability in Ghidra by National Security Agency
CVE-2026-49496
6.9MEDIUM
What is CVE-2026-49496?
A heap-use-after-free vulnerability exists in Ghidra prior to version 12.1, specifically in the SleighBuilder::generatePointerAdd function. This vulnerability arises due to iterator invalidation when the PcodeCacher::allocateInstruction reallocates the issued vector. Attackers can exploit this flaw by decompiling specially crafted malicious binaries via the public Sleigh::oneInstruction C++ API, resulting in memory corruption that affects consumers of the SLEIGH library.
Affected Version(s)
ghidra 0 < 12.1
ghidra 12.1
