CVE-2026-52753

Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded output buffers without size limits. Attackers can craft malicious Rust symbol names in binaries to trigger exponential memory allocation, causing process crashes during binary analysis.
Configurations

No configuration.

History

10 Jun 2026, 16:17

Type Values Removed Values Added
References () https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-m94m-fqr3-x442 - () https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-m94m-fqr3-x442 -

10 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 14:16

Updated : 2026-06-10 16:17


NVD link : CVE-2026-52753

Mitre link : CVE-2026-52753

CVE.ORG link : CVE-2026-52753


JSON object : View

Products Affected

No product.

CWE
CWE-789

Memory Allocation with Excessive Size Value