CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.




CodeChecker versions up to 6.26.1 contain a buffer overflow vulnerability in the internal ldlogger library, which is executed by the CodeChecker log command.





This issue affects CodeChecker: through 6.26.1.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-30823 CodeChecker has a buffer overflow in the log command
Github GHSA Github GHSA GHSA-5xf2-f6ch-6p8r CodeChecker has a buffer overflow in the log command
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 29 Oct 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Ericsson
Ericsson codechecker
Vendors & Products Ericsson
Ericsson codechecker

Tue, 28 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Oct 2025 19:00:00 +0000

Type Values Removed Values Added
Description CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. CodeChecker versions up to 6.26.1 contain a buffer overflow vulnerability in the internal ldlogger library, which is executed by the CodeChecker log command. This issue affects CodeChecker: through 6.26.1.
Title Buffer overflow in CodeChecker log command
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ERIC

Published:

Updated: 2025-10-28T19:30:25.737Z

Reserved: 2025-04-16T08:59:01.744Z

Link: CVE-2025-40843

cve-icon Vulnrichment

Updated: 2025-10-28T19:30:21.796Z

cve-icon NVD

Status : Received

Published: 2025-10-28T19:15:41.757

Modified: 2025-10-28T19:15:41.757

Link: CVE-2025-40843

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-29T10:57:43Z