7

CVE-2025-5222

Icu: stack buffer overflow in the srbroot::addtag function

A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.285
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

https://bugzilla.redhat.com/show_bug.cgi?id=2368600
Issue Tracking
https://lists.debian.org/debian-lts-announce/2025/06/msg00015.html
Mailing List
https://cert-portal.siemens.com/productcert/html/ssa-585531.html
https://access.redhat.com/errata/RHSA-2025:11888
Vendor Advisory
https://access.redhat.com/errata/RHSA-2025:12083
Vendor Advisory
https://access.redhat.com/errata/RHSA-2025:12331
Vendor Advisory
https://access.redhat.com/errata/RHSA-2025:12332
Vendor Advisory
https://access.redhat.com/errata/RHSA-2025:12333
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2025-5222
Vendor Advisory
https://unicode-org.atlassian.net/jira/software/c/projects/ICU/issues/ICU-22957
https://access.redhat.com/errata/RHSA-2026:54581
https://access.redhat.com/errata/RHSA-2026:54553
https://access.redhat.com/errata/RHSA-2026:54544
https://access.redhat.com/errata/RHSA-2026:56786
https://access.redhat.com/errata/RHSA-2026:56853
https://access.redhat.com/errata/RHSA-2026:56911
https://access.redhat.com/errata/RHSA-2026:60019
https://access.redhat.com/errata/RHSA-2026:65839