7
CVE-2025-5222
- EPSS 0.35%
- Veröffentlicht 27.05.2025 20:51:50
- Zuletzt bearbeitet 17.09.2026 19:16:36
- Erkennungen
Icu: stack buffer overflow in the srbroot::addtag function
A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Unicode ≫ International Components For Unicode Version < 77.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.285 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
https://bugzilla.redhat.com/show_bug.cgi?id=2368600
https://lists.debian.org/debian-lts-announce/2025/06/msg00015.html
https://cert-portal.siemens.com/productcert/html/ssa-585531.html
https://access.redhat.com/errata/RHSA-2025:11888
https://access.redhat.com/errata/RHSA-2025:12083
https://access.redhat.com/errata/RHSA-2025:12331
https://access.redhat.com/errata/RHSA-2025:12332
https://access.redhat.com/errata/RHSA-2025:12333
https://access.redhat.com/security/cve/CVE-2025-5222
https://unicode-org.atlassian.net/jira/software/c/projects/ICU/issues/ICU-22957
https://access.redhat.com/errata/RHSA-2026:54581
https://access.redhat.com/errata/RHSA-2026:54553
https://access.redhat.com/errata/RHSA-2026:54544
https://access.redhat.com/errata/RHSA-2026:56786
https://access.redhat.com/errata/RHSA-2026:56853
https://access.redhat.com/errata/RHSA-2026:56911
https://access.redhat.com/errata/RHSA-2026:60019
https://access.redhat.com/errata/RHSA-2026:65839