CVE-2025-11010

NameCVE-2025-11010
DescriptionA vulnerability has been found in vstakhov libucl up to 0.9.2. Affected by this vulnerability is the function ucl_include_common of the file /src/ucl_util.c. Such manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

https://github.com/vstakhov/libucl/issues/337
check if impacts security wise rspamd, which embeds libucl and uses it a compile time

Search for package or bug name: Reporting problems