Ghidra 12.1.4 及更早版本中存在一个基于栈的越界写漏洞,该漏洞出现在反编译器的 leftshift128 函数中,当处理来自 p-code 的负数移位量时触发。攻击者可以构造包含特定指令序列的恶意二进制文件,在反编译时引发溢出,从而破坏内存,并可能实现代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NationalSecurityAgency | ghidra | 0 ~ 12.1.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100505 | 4.4 MEDIUM | Ghidra 11.2 through 12.1.4 Heap Out-of-Bounds Read via StringManager |
| CVE-2026-100503 | 3.3 LOW | Ghidra through 12.1.4 Heap Use-After-Free in Decompiler |
No comments yet