Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4217-1 | icu security update |
Debian DSA |
DSA-5951-1 | icu security update |
EUVD |
EUVD-2025-16306 | A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution. |
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Fri, 08 Aug 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Unicode
Unicode international Components For Unicode |
|
| CPEs | cpe:2.3:a:unicode:international_components_for_unicode:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Unicode
Unicode international Components For Unicode |
Thu, 31 Jul 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel Eus
|
|
| CPEs | cpe:/a:redhat:rhel_e4s:9.0::appstream cpe:/a:redhat:rhel_eus:9.4::appstream cpe:/o:redhat:rhel_e4s:9.0::baseos cpe:/o:redhat:rhel_eus:9.4::baseos |
|
| Vendors & Products |
Redhat rhel Eus
|
|
| References |
|
Thu, 31 Jul 2025 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel E4s
|
|
| CPEs | cpe:/a:redhat:rhel_e4s:9.2::appstream cpe:/o:redhat:rhel_e4s:9.2::baseos |
|
| Vendors & Products |
Redhat rhel E4s
|
|
| References |
|
Tue, 29 Jul 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:enterprise_linux:9::appstream cpe:/o:redhat:enterprise_linux:9::baseos |
|
| References |
|
Mon, 28 Jul 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/o:redhat:enterprise_linux:10.0 | |
| References |
|
Sun, 15 Jun 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 28 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 May 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution. |
| Title | icu: Stack buffer overflow in the SRBRoot::addTag function | Icu: stack buffer overflow in the srbroot::addtag function |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| CPEs | cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| References |
|
Tue, 27 May 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | icu: Stack buffer overflow in the SRBRoot::addTag function | |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-07-31T04:59:35.421Z
Reserved: 2025-05-26T14:41:58.427Z
Link: CVE-2025-5222
Updated: 2025-06-15T23:02:56.243Z
Status : Analyzed
Published: 2025-05-27T21:15:23.030
Modified: 2025-08-08T14:55:36.747
Link: CVE-2025-5222
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD