Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. Attackers can craft a malicious binary with a specific x86-64 sequence that triggers the vulnerability during decompilation, causing the decompile helper process to crash and denying service to analysts and automated analysis pipelines.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 26 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. Attackers can craft a malicious binary with a specific x86-64 sequence that triggers the vulnerability during decompilation, causing the decompile helper process to crash and denying service to analysts and automated analysis pipelines. | |
| Title | Ghidra through 12.1.4 Heap Use-After-Free in Decompiler | |
| First Time appeared |
Nsa
Nsa ghidra |
|
| Weaknesses | CWE-416 | |
| CPEs | cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nsa
Nsa ghidra |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T00:36:31.894Z
Reserved: 2026-09-25T22:14:31.017Z
Link: CVE-2026-100503
No data.
Status : Received
Published: 2026-09-26T01:16:59.880
Modified: 2026-09-26T01:16:59.880
Link: CVE-2026-100503
No data.
OpenCVE Enrichment
No data.
Weaknesses