6.8
CVE-2026-96273
- EPSS 0.12%
- Veröffentlicht 23.09.2026 00:29:51
- Zuletzt bearbeitet 28.09.2026 17:17:53
- Erkennungen
Ghidra before 12.1.4 Denial of Service via Unreleased Lock in OptionsDB
Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leaves domain objects permanently locked. Attackers can craft a malicious program database file that, when imported, causes the application to stall and prevents resource cleanup or graceful shutdown.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNationalSecurityAgency
≫
Produkt
ghidra
Default Statusunaffected
Version
0
Version <
12.1.4
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.017 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 6.8 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
CWE-460 Improper Cleanup on Thrown Exception
The product does not clean up its state or incorrectly cleans up its state when an exception is thrown, leading to unexpected state or control flow.
CWE-667 Improper Locking
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.
https://github.com/NationalSecurityAgency/ghidra
https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-4w7g-wmg8-fgv5
https://github.com/NationalSecurityAgency/ghidra/commit/594da048431aab082a9da7c4a965874d07d33310
https://github.com/NationalSecurityAgency/ghidra/blob/Ghidra_12.1.3_build/Ghidra/Framework/Project/src/main/java/ghidra/framework/data/OptionsDB.java#L358-L366
https://github.com/NationalSecurityAgency/ghidra/releases/tag/Ghidra_12.1.4_build
https://www.vulncheck.com/advisories/ghidra-before-12.1.4-denial-of-service-via-crafted-database