The vendor explicitly identifies these products as affected by this CVE.
- capstone as a component of Red Hat Enterprise Linux 10
- capstone-devel as a component of Red Hat Enterprise Linux 10
- capstone-java as a component of Red Hat Enterprise Linux 10
- capstone.src as a component of Red Hat Enterprise Linux 10
- python3-capstone as a component of Red Hat Enterprise Linux 10
- capstone as a component of Red Hat Enterprise Linux 9
- capstone-devel as a component of Red Hat Enterprise Linux 9
- capstone-java as a component of Red Hat Enterprise Linux 9
- capstone.src as a component of Red Hat Enterprise Linux 9
- python3-capstone as a component of Red Hat Enterprise Linux 9
- capstone.src as a component of Red Hat Hardened Images
- openshift/ose-rhel-coreos-9 as a component of Red Hat OpenShift Container Platform 4
- Summary
- A flaw was found in Capstone. The `cs_insn_name()` application programming interface (API) in the M68K and RISCV backends does not properly validate caller-supplied instruction IDs. An attacker can provide an invalid instruction ID, leading to an out-of-bounds read. This can cause the process to crash, resulting in a denial of service (DoS) for applications that expose instruction-name lookup to untrusted IDs.
- Remediation
- Fix deferred
