Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25164 | A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This affects the function filestream_vscanf of the file libretro-common/streams/file_stream.c. This manipulation causes out-of-bounds read. The attack needs to be launched locally. Upgrading to version 1.21.0 mitigates this issue. It is recommended to upgrade the affected component. |
Fri, 12 Sep 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:libretro:retroarch:1.18.0:*:*:*:*:*:*:* cpe:2.3:a:libretro:retroarch:1.19.0:*:*:*:*:*:*:* cpe:2.3:a:libretro:retroarch:1.20.0:*:*:*:*:*:*:* |
Thu, 21 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libretro
Libretro retroarch |
|
| Vendors & Products |
Libretro
Libretro retroarch |
Tue, 19 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 Aug 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This affects the function filestream_vscanf of the file libretro-common/streams/file_stream.c. This manipulation causes out-of-bounds read. The attack needs to be launched locally. Upgrading to version 1.21.0 mitigates this issue. It is recommended to upgrade the affected component. | |
| Title | libretro RetroArch file_stream.c filestream_vscanf out-of-bounds | |
| Weaknesses | CWE-119 CWE-125 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-08-19T13:15:15.055Z
Reserved: 2025-08-19T05:30:17.042Z
Link: CVE-2025-9136
Updated: 2025-08-19T13:14:53.430Z
Status : Analyzed
Published: 2025-08-19T12:15:27.390
Modified: 2025-09-12T14:55:08.680
Link: CVE-2025-9136
No data.
OpenCVE Enrichment
Updated: 2025-08-21T12:32:00Z
EUVD