Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a1618be12017d7d41e0b6581d5d529e fixes the issue.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 02 Jan 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:capstone-engine:capstone:*:*:*:*:*:*:*:* cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha1:*:*:*:*:*:* cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha2:*:*:*:*:*:* cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha3:*:*:*:*:*:* cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha4:*:*:*:*:*:* cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha5:*:*:*:*:*:* |
Wed, 24 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 18 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Capstone-engine
Capstone-engine capstone |
|
| Vendors & Products |
Capstone-engine
Capstone-engine capstone |
Wed, 17 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a1618be12017d7d41e0b6581d5d529e fixes the issue. | |
| Title | Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow | |
| Weaknesses | CWE-120 CWE-124 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-18T15:09:11.561Z
Reserved: 2025-12-15T16:16:22.744Z
Link: CVE-2025-68114
No data.
Status : Analyzed
Published: 2025-12-17T22:16:01.400
Modified: 2026-01-02T18:33:09.800
Link: CVE-2025-68114
OpenCVE Enrichment
Updated: 2025-12-18T09:56:03Z