CVE-2026-55894
Discovered by AISLEPUBLISHEDCWE-125
Description
Capstone SH disassembler `sh_disassemble` out-of-bounds read via crafted SH2A bytecode
CVSS Base Scores
CVSS v4.06.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Version | Status |
|---|---|---|---|
| capstone-engine | Capstone | < 6.0.0-Alpha10 | affected |
References
- https://github.com/capstone-engine/capstone/security/advisories/GHSA-gf2c-xwcp-hvf4
- https://github.com/capstone-engine/capstone/pull/2968
- https://github.com/capstone-engine/capstone/pull/2969
- https://github.com/capstone-engine/capstone/commit/09e76802380b9e94d9720c44458d9d5282219e7e
- https://github.com/capstone-engine/capstone/commit/e17ee44a8307ea33375b4727ac4f987650bf7bed
- https://github.com/capstone-engine/capstone/releases/tag/6.0.0-Alpha10

