CyberRota Analysis
AI-GeneratedGhidra versions 11.2 through 12.1.4 are vulnerable to a heap out-of-bounds read due to improper validation of buffer lengths when decoding multi-byte character encodings. This flaw can be exploited by attackers to crash the decompiler or potentially leak sensitive information from adjacent memory. Organizations using Ghidra for binary analysis should prioritize patching this vulnerability to mitigate risks associated with malicious binaries.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Ghidra versions 9.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating remaining buffer length. Attackers can craft malicious binaries containing strings or constant byte stores that end in multi-byte lead units to trigger out-of-bounds reads that crash the decompiler or leak adjacent heap memory into decompiled output.
Related CVEs
Other vulnerabilities affecting the same vendor(s)