CVE-2025-40843

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. CodeChecker versions up to 6.26.1 contain a buffer overflow vulnerability in the internal ldlogger library, which is executed by the CodeChecker log command. This issue affects CodeChecker: through 6.26.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ericsson:codechecker:*:*:*:*:*:*:*:*

History

14 Nov 2025, 18:52

Type Values Removed Values Added
References () https://github.com/Ericsson/codechecker/security/advisories/GHSA-5xf2-f6ch-6p8r - () https://github.com/Ericsson/codechecker/security/advisories/GHSA-5xf2-f6ch-6p8r - Exploit, Vendor Advisory
First Time Ericsson
Ericsson codechecker
CPE cpe:2.3:a:ericsson:codechecker:*:*:*:*:*:*:*:*

28 Oct 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-28 19:15

Updated : 2025-11-14 18:52


NVD link : CVE-2025-40843

Mitre link : CVE-2025-40843

CVE.ORG link : CVE-2025-40843


JSON object : View

Products Affected

ericsson

  • codechecker
CWE
CWE-121

Stack-based Buffer Overflow