Uncontrolled Recursion in Ghidra - #VU151851

 

Uncontrolled Recursion in Ghidra - #VU151851

Published: September 23, 2026


Vulnerability identifier: #VU151851
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-674
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled recursion in PEx64UnwindInfo.readUnwindInfo() when parsing cyclic x64 chained-unwind metadata. A remote attacker can provide a crafted PE32+ file for import to cause a denial of service.

User interaction is required to import the crafted file. Ghidra does not execute the PE while parsing it.


Affected software

Ghidra

Remediation

Install security update from vendor's website.

Ghidra - update to 12.1.4

External References

Related Security Bulletins