CVE-2026-55893
Discovered by AISLEPUBLISHEDCWE-122
Description
Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecode
CVSS Base Scores
CVSS v4.06.5
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Version | Status |
|---|---|---|---|
| capstone-engine | Capstone | < 6.0.0-Alpha10 | affected |
References
- https://github.com/capstone-engine/capstone/security/advisories/GHSA-3hpv-wr3j-rxwh
- https://github.com/capstone-engine/capstone/pull/2968
- https://github.com/capstone-engine/capstone/pull/2969
- https://github.com/capstone-engine/capstone/commit/09e76802380b9e94d9720c44458d9d5282219e7e
- https://github.com/capstone-engine/capstone/commit/e17ee44a8307ea33375b4727ac4f987650bf7bed
- https://github.com/capstone-engine/capstone/releases/tag/6.0.0-Alpha10

