Bug 2387304 (CVE-2025-8734) - CVE-2025-8734 bison: Bison Double Free Vulnerability
Summary: CVE-2025-8734 bison: Bison Double Free Vulnerability
Keywords:
Status: NEW
Alias: CVE-2025-8734
Product: Security Response
Classification: Other
Component: vulnerability-draft
Version: unspecified
Hardware: All
OS: Linux
unspecified
unspecified
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2387629 2387630
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-08-08 19:02 UTC by OSIDB Bzimport
Modified: 2025-12-03 06:51 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-08-08 19:02:22 UTC
A vulnerability classified as problematic has been found in GNU Bison up to 3.8.2. Affected is the function code_free of the file src/scan-code.c. The manipulation leads to double free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.


Note You need to log in before you can comment on or make changes to this bug.