Impact
Ghidra versions prior to 12.1.4 fail to validate the TYPE_COL byte when creating an unregistered option, which can trigger an ArrayIndexOutOfBoundsException during database creation. The exception causes domain objects to remain permanently locked, preventing normal application shutdown and leaving the tool in a stalled state. The primary impact is a denial of service that can render the entire Ghidra session unusable until a restart or manual intervention resolves the locked state.
Affected Systems
National Security Agency’s Ghidra software, versions earlier than 12.1.4, is affected. Any installation running an unpatched database engine is vulnerable, regardless of the operating system.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, and the EPSS score is not available, so the likelihood of exploitation in the wild is unclear. The vulnerability is listed as not in the CISA KEV catalog and is exploitable through the import of a crafted program database, meaning any user with the ability to supply such a file could trigger the denial of service. This local attack vector does not allow remote code execution but can disrupt analysis workflows and lead to resource exhaustion.
OpenCVE Enrichment