Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a1618be12017d7d41e0b6581d5d529e fixes the issue.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 03 Jan 2026 03:45:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:capstone-engine:capstone:*:*:*:*:*:*:*:*
cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha5:*:*:*:*:*:*

Wed, 24 Dec 2025 09:15:00 +0900

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 18 Dec 2025 19:00:00 +0900

Type Values Removed Values Added
First Time appeared Capstone-engine
Capstone-engine capstone
Vendors & Products Capstone-engine
Capstone-engine capstone

Thu, 18 Dec 2025 06:30:00 +0900

Type Values Removed Values Added
Description Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a1618be12017d7d41e0b6581d5d529e fixes the issue.
Title Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow
Weaknesses CWE-120
CWE-124
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-18T15:09:11.561Z

Reserved: 2025-12-15T16:16:22.744Z

Link: CVE-2025-68114

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2025-12-17T22:16:01.400

Modified: 2026-01-02T18:33:09.800

Link: CVE-2025-68114

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-12-17T21:14:31Z

Links: CVE-2025-68114 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-12-18T18:56:03Z

Weaknesses