CVE-2025-49589

NameCVE-2025-49589
DescriptionPCSX2 is a free and open-source PlayStation 2 (PS2) emulator. A stack-based buffer overflow exists in the Kprintf_HLE function of PCSX2 versions up to 2.3.414. Opening a disc image that logs a specially crafted message may allow a remote attacker to execute arbitrary code if the user enabled IOP Console Logging. This vulnerability is fixed in 2.3.414.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1107756

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pcsx2 (PTS)bullseye1.6.0+dfsg-1vulnerable
bookworm1.6.0+dfsg-2vulnerable
sid, trixie1.6.0+dfsg-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pcsx2source(unstable)(unfixed)1107756

Notes

[bookworm] - pcsx2 <no-dsa> (Minor issue)
[bullseye] - pcsx2 <postponed> (Minor issue)
https://github.com/PCSX2/pcsx2/security/advisories/GHSA-f494-4xf7-xj35
https://github.com/PCSX2/pcsx2/commit/1aa922f7007afe71e0b58b0c3bd0833a53cb945c (v2.3.411)
https://github.com/PCSX2/pcsx2/commit/8eb46b5a4c0380d59cb540f8b5f59daf8e609bd7 (v2.3.414)

Search for package or bug name: Reporting problems