Use-after-free in Ghidra - #VU127893

 

Use-after-free in Ghidra - #VU127893

Published: September 19, 2024 / Updated: April 25, 2026


Vulnerability identifier: #VU127893
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in SleighArchitecture::shutdown in the Sleigh decompiler backend when destroying global singletons in an undefined order during shutdown. A remote attacker can trigger the vulnerable shutdown sequence to cause a denial of service.

This issue occurs during shutdown and was observed to cause an infinite loop by iterating over garbage data.


Affected software

Ghidra

Remediation

Install security update from vendor's website.

Ghidra - update to 11.2

External References

Related Security Bulletins