CyberRota Analysis
AI-GeneratedGhidra versions up to 12.1.4 are vulnerable to a stack-based out-of-bounds write in the decompiler's leftshift128 function, which can be exploited by attackers using specially crafted binaries to trigger memory corruption. This vulnerability poses a high risk of code execution, making it critical for users and organizations relying on Ghidra for reverse engineering to prioritize updates and mitigations. Immediate action is advised to safeguard against potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. Attackers can craft malicious binaries with specific instruction sequences that trigger the overflow when decompiled, corrupting memory and potentially achieving code execution.
Related CVEs
Other vulnerabilities affecting the same vendor(s)