cmake cmForEachCommand.cxx ReplayItems assertion
Vulnerability Description
A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::ReplayItems of the file cmForEachCommand.cxx. This manipulation causes reachable assertion. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. Patch name: 37e27f71bc356d880c908040cd0cb68fa2c371b8. It is suggested to install a patch to address this issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9301
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- xdcao (VulDB User)
References
- https://vuldb.com/?id.320906
- https://vuldb.com/?ctiid.320906
- https://vuldb.com/?submit.632369
- https://gitlab.kitware.com/cmake/cmake/-/issues/27135
- https://gitlab.kitware.com/cmake/cmake/-/issues/27135#note_1691629
- https://drive.google.com/file/d/1TerUqQB8_lzJTwIBCBmE94zn7n-gOz4f/view?usp=sharing
- https://gitlab.kitware.com/cmake/cmake/-/commit/37e27f71bc356d880c908040cd0cb68fa2c371b8