CVE-2025-67873 - CVE House
Back to Database
Status published Medium CVE-2025-67873

Capstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow

Vulnerability Description

Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, Skipdata length is not bounds-checked, so a user-provided skipdata callback can make cs_disasm/cs_disasm_iter memcpy more than 24 bytes into cs_insn.bytes, causing a heap buffer overflow in the disassembly path. Commit cbef767ab33b82166d263895f24084b75b316df3 fixes the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-67873

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

capstone-engine

View all reports →

Affected Software

capstone
Vulnerable Versions:
<= 6.0.0-Alpha5

Timeline

Official Publish: December 17th, 2025
Last Modified: December 18th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

Weaknesses (CWE)