Stack-based buffer overflow in Helm - CVE-2025-32387

 

Stack-based buffer overflow in Helm - CVE-2025-32387

Published: June 26, 2025


Vulnerability identifier: #VU111974
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-32387
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. A remote unauthenticated attacker can craft a JSON Schema file within a chart with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack overflow.


Affected software

Helm
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Containers Module
openSUSE Leap
Kubecost Self Hosted
IBM Cloud Pak for Watson AIOps
IBM Fusion HCI
Cloud Pak for Data
helm-mirror-debuginfo
helm-mirror

How to mitigate CVE-2025-32387

Install updates from vendor's website.

Helm - update to 3.17.3
IBM Fusion HCI - update to 2.11.0
IBM Cloud Pak for Watson AIOps - update to 4.10.0
Cloud Pak for Data - update to 5.0.1
helm-mirror-debuginfo - update to 0.3.1-150000.1.18.2
helm-mirror - update to 0.3.1-150000.1.18.2

External References

Related Security Bulletins