Stack Overflow Vulnerability in CodeChecker by Ericsson
CVE-2026-58106

2LOW

Key Information:

Vendor

Ericsson

Vendor
CVE Published:
28 August 2026

What is CVE-2026-58106?

A stack overflow vulnerability exists in CodeChecker prior to version 6.28.2, resulting from improper usage of the safe_strcpy() function. The design flaw arises when the function writes beyond the allocated buffer size, causing a two-byte stack overflow each time it is invoked. This vulnerability can be exploited by providing a path longer than the defined limits, leading to potential overwrites and unpredictable application behavior.

Affected Version(s)

CodeChecker 0 <= 6.28.2

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fatullayev Asadbek
.