Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Ghidra < 12.1 - Heap-Use-After-Free in SleighBuilder::generatePointerAdd via Vector Reallocation
Vulnerability Description
Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator invalidation when PcodeCacher::allocateInstruction reallocates the issued vector. Attackers can trigger memory corruption by decompiling malicious binaries through the public Sleigh::oneInstruction C++ API, affecting downstream SLEIGH library consumers.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Vulnerability Type
释放后使用
Vulnerability Title
NSA Ghidra 资源管理错误漏洞
Vulnerability Description
NSA Ghidra是美国国家安全局(National Security Agency)的一款开源逆向工程工具。 NSA Ghidra 12.1之前版本存在资源管理错误漏洞,该漏洞源于SleighBuilder::generatePointerAdd中迭代器失效导致释放后重用,攻击者可通过公共Sleigh::oneInstruction C++ API反编译恶意二进制文件触发内存损坏,影响下游SLEIGH库使用者。
CVSS Information
N/A
Vulnerability Type
N/A