GHSA-m3q7-8jjf-cmcwHighCVSS 7.0

Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the...

Published
September 26, 2026
Last Modified
September 26, 2026

🔗 CVE IDs covered (1)

📋 Description

Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. Attackers can craft malicious binaries with specific instruction sequences that trigger the overflow when decompiled, corrupting memory and potentially achieving code execution.

🔗 References (7)