CVE-2026-100503
MEDIUM
4,8
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
LOW
3,3
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: low
Description
AI Translation Available
Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. Attackers can craft a malicious binary with a specific x86-64 sequence that triggers the vulnerability during decompilation, causing the decompile helper process to crash and denying service to analysts and automated analysis pipelines.
416
Use After Free
StableCommon Consequences
Security Scopes Affected:
Integrity
Availability
Confidentiality
Potential Impacts:
Modify Memory
Dos: Crash, Exit, Or Restart
Read Memory
Execute Unauthorized Code Or Commands
Applicable Platforms
Languages:
Memory-Unsafe, C, C++
https://github.com/NationalSecurityAgency/ghidra
https://github.com/NationalSecurityAgency/ghidra/blob/8b6bbb857accdfa20dc5b2f5d…
https://github.com/NationalSecurityAgency/ghidra/blob/8b6bbb857accdfa20dc5b2f5d…
https://github.com/NationalSecurityAgency/ghidra/commit/5ef1ee4d7a25a65db195f3a…
https://www.vulncheck.com/advisories/ghidra-through-12.1.4-heap-use-after-free-…