LOWCVSS 3.3
Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. Attackers can craft a malicious binary with a specific x86-64 sequence that triggers the vulnerability during decompilation, causing the decompile helper process to crash and denying service to analysts and automated analysis pipelines.
Published 2026-09-26 · last modified 2026-09-26
| Vendor | Product |
|---|---|
| nationalsecurityagency | ghidra |
Ncerio by BeyondNets · data from NVD, CISA KEV, EPSS.