Bug 2521147 - CVE-2025-68114 rust: Capstone: Memory corruption via unchecked vsnprintf return [fedora-43]
Summary: CVE-2025-68114 rust: Capstone: Memory corruption via unchecked vsnprintf retu...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: rust
Version: 43
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Rust SIG
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["18ccc59d-83a6-4a40-84de-3...
Depends On:
Blocks: CVE-2025-68114
TreeView+ depends on / blocked
 
Reported: 2026-08-21 19:53 UTC by Praise Ogwuche
Modified: 2026-08-21 22:10 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-08-21 20:45:13 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Praise Ogwuche 2026-08-21 19:53:29 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a1618be12017d7d41e0b6581d5d529e fixes the issue.

Comment 1 Paul Murphy 2026-08-21 20:45:13 UTC
capstone is not used nor built by the rust package.

@pogwuche in more recent updates to rust packaging, the capstone source included with the original rust source, but is removed during the prep stage. Do you know if that is sufficient to prevent reporting false positives?

Comment 2 Praise Ogwuche 2026-08-21 22:10:33 UTC
Yes. If is is removed during the prep stage and the final package doesn’t build or ship capstone, that’s sufficient. we’d set as not affected on our end going forward(if it happens to appear in our manifest).


Note You need to log in before you can comment on or make changes to this bug.