CodeChecker versions up to 6.26.1 contain a buffer overflow vulnerability in the internal ldlogger library, which is executed by the CodeChecker log command.
This issue affects CodeChecker: through 6.26.1.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-30823 | CodeChecker has a buffer overflow in the log command |
Github GHSA |
GHSA-5xf2-f6ch-6p8r | CodeChecker has a buffer overflow in the log command |
Fri, 14 Nov 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ericsson:codechecker:*:*:*:*:*:*:*:* |
Wed, 29 Oct 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ericsson
Ericsson codechecker |
|
| Vendors & Products |
Ericsson
Ericsson codechecker |
Tue, 28 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. CodeChecker versions up to 6.26.1 contain a buffer overflow vulnerability in the internal ldlogger library, which is executed by the CodeChecker log command. This issue affects CodeChecker: through 6.26.1. | |
| Title | Buffer overflow in CodeChecker log command | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ERIC
Published:
Updated: 2025-10-28T19:30:25.737Z
Reserved: 2025-04-16T08:59:01.744Z
Link: CVE-2025-40843
Updated: 2025-10-28T19:30:21.796Z
Status : Analyzed
Published: 2025-10-28T19:15:41.757
Modified: 2025-11-14T18:52:30.597
Link: CVE-2025-40843
No data.
OpenCVE Enrichment
Updated: 2025-10-29T10:57:43Z
EUVD
Github GHSA