Heap-based buffer overflow in Ghidra - #VU144380

 

Heap-based buffer overflow in Ghidra - #VU144380

Published: August 19, 2026


Vulnerability identifier: #VU144380
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service or modify memory.

The vulnerability exists due to a heap-based buffer overflow in TypeFactory::getBase() when processing a crafted binary during jump table recovery. A remote attacker can trick the victim into opening a crafted binary to cause a denial of service or modify memory.

User interaction is required to open the crafted binary or run headless analysis on it.


Affected software

Ghidra

Remediation

Install security update from vendor's website.

Ghidra - update to 12.1.3

External References

Related Security Bulletins