Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Jan 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:capstone-engine:capstone:*:*:*:*:*:*:*:* cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha1:*:*:*:*:*:* cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha2:*:*:*:*:*:* cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha3:*:*:*:*:*:* cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha4:*:*:*:*:*:* cpe:2.3:a:capstone-engine:capstone:6.0.0:alpha5:*:*:*:*:*:* |
Wed, 24 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 18 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Capstone-engine
Capstone-engine capstone |
|
| Vendors & Products |
Capstone-engine
Capstone-engine capstone |
Wed, 17 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, Skipdata length is not bounds-checked, so a user-provided skipdata callback can make cs_disasm/cs_disasm_iter memcpy more than 24 bytes into cs_insn.bytes, causing a heap buffer overflow in the disassembly path. Commit cbef767ab33b82166d263895f24084b75b316df3 fixes the issue. | |
| Title | Capstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-18T15:09:19.484Z
Reserved: 2025-12-12T18:53:03.237Z
Link: CVE-2025-67873
Updated: 2025-12-18T14:56:03.352Z
Status : Analyzed
Published: 2025-12-17T22:16:00.147
Modified: 2026-01-02T18:39:54.833
Link: CVE-2025-67873
OpenCVE Enrichment
Updated: 2025-12-18T09:56:08Z