The vendor explicitly identifies these products as affected by this CVE.
- capstone as a component of Red Hat Enterprise Linux 10
- capstone-devel as a component of Red Hat Enterprise Linux 10
- capstone-java as a component of Red Hat Enterprise Linux 10
- capstone.src as a component of Red Hat Enterprise Linux 10
- python3-capstone as a component of Red Hat Enterprise Linux 10
- capstone as a component of Red Hat Enterprise Linux 9
- capstone-devel as a component of Red Hat Enterprise Linux 9
- capstone-java as a component of Red Hat Enterprise Linux 9
- capstone.src as a component of Red Hat Enterprise Linux 9
- python3-capstone as a component of Red Hat Enterprise Linux 9
- capstone.src as a component of Red Hat Hardened Images
- openshift/ose-rhel-coreos-9 as a component of Red Hat OpenShift Container Platform 4
- Summary
- A flaw was found in Capstone, a disassembly framework, affecting its WebAssembly (WASM) backend. A remote attacker could exploit this by providing a specially crafted `br_table` instruction. This could lead to a denial of service, where the disassembler gets stuck in a loop, or cause parser desynchronization, leading to incorrect disassembly of subsequent instructions. This issue impacts the availability and integrity of the disassembler.
- Remediation
- Fix deferred
