libretro RetroArch file_stream.c filestream_vscanf out-of-bounds
Vulnerability Description
A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This affects the function filestream_vscanf of the file libretro-common/streams/file_stream.c. This manipulation causes out-of-bounds read. The attack needs to be launched locally. Upgrading to version 1.21.0 mitigates this issue. It is recommended to upgrade the affected component.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9136
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Simcha Kosman
- simkca (VulDB User)
References
- https://vuldb.com/?id.320516
- https://vuldb.com/?ctiid.320516
- https://vuldb.com/?submit.617657
- https://github.com/libretro/RetroArch/pull/17555
- https://github.com/libretro/RetroArch/pull/17555#issuecomment-2651403849
- https://github.com/libretro/RetroArch/pull/17555/commits/6446f045ec7fc6a5cac3e8ec35a2f0a5889c88e8
- https://github.com/libretro/RetroArch/releases/tag/v1.21.0
More from libretro
View All →Affected Vendor
libretro
View all reports →