Stack-based buffer overflow in icu - CVE-2025-5222
Published: August 14, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the SRBRoot::addTag() function in genrb binary. A remote unauthenticated attacker can pass a specially crafted input to the application, trigger a stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Basesystem Module
openEuler
Anolis OS
Fedora
IBM Observability with Instana
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
icu-debuginfo
libicu60_2-ledata
libicu60_2-bedata
libicu60_2-debuginfo
icu-debugsource
libicu60_2
icu (Red Hat package)
libicu-doc
libicu-devel
libicu
icu
icu (Debian package)
icu-help
mingw-icu
IBM API Connect
Business Automation Insights
Red Hat OpenShift Container Platform
Red Hat Ceph Storage
How to mitigate CVE-2025-5222
IBM Observability with Instana - update to 1.0.309
IBM API Connect - update to 10.0.8.5
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3
Red Hat OpenShift Container Platform - addressed in versions 4.15.56, 4.16.46, 4.18.22, 4.18.53
Red Hat Ceph Storage - update to 7.1
icu-debuginfo - update to 60.2-150000.3.18.1
libicu60_2-ledata - update to 60.2-150000.3.18.1
libicu60_2-bedata - update to 60.2-150000.3.18.1
libicu60_2-debuginfo - update to 60.2-150000.3.18.1
icu-debugsource - update to 60.2-150000.3.18.1
libicu60_2 - update to 60.2-150000.3.18.1
icu (Red Hat package) - addressed in versions 67.1-10.el9_0, 67.1-10.el9_2, 67.1-10.el9_4, 67.1-10.el9_6, 74.2-5.el10_0
libicu-doc - update to 72.1-3
libicu-devel - update to 72.1-3
libicu - update to 72.1-3
icu - update to 72.1-3
icu (Debian package) - update to 72.1-3+deb12u1
libicu - update to 74.1-4
libicu-devel - update to 74.1-4
icu-debugsource - update to 74.1-4
icu-debuginfo - update to 74.1-4
icu - update to 74.1-4
icu-help - update to 74.1-4
mingw-icu - addressed in versions 74.2-4.fc41, 76.1-3.fc42
External References
Related Security Bulletins
- Debian update for icu
- Remote code execution in Internationl components for unicode (ICU)
- Fedora 41 update for mingw-icu
- Fedora 42 update for mingw-icu
- Fedora 41 update for mingw-icu
- Fedora 42 update for mingw-icu
- openEuler update for icu
- Red Hat Enterprise Linux 10 update for icu
- Red Hat Enterprise Linux 10 update for icu
- Red Hat Enterprise Linux 9 update for icu
- Red Hat Enterprise Linux 9 update for icu
- Red Hat Enterprise Linux 9 update for icu
- Red Hat Enterprise Linux 9 update for icu
- Red Hat Enterprise Linux 9 update for icu
- Red Hat Enterprise Linux 9 update for icu
- Red Hat Enterprise Linux 9 update for icu
- Red Hat Enterprise Linux 9 update for icu
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- SUSE update for icu
- SUSE update for icu
- SUSE update for icu
- Anolis OS update for icu
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18