Use-after-free in Ghidra - #VU131582
Published: May 15, 2026
Ghidra
Detailed vulnerability description
The vulnerability allows a remote attacker to corrupt memory or cause a denial of service.
The vulnerability exists due to use-after-free in HighVariable::merge() and HighIntersectTest::highedgemap cache handling when decompiling a crafted binary. A remote attacker can trick the victim into opening a crafted binary to corrupt memory or cause a denial of service.
User interaction is required to open the decompiler view or otherwise trigger decompilation, including through analyzeHeadless.