CVE-2026-47143

NameCVE-2026-47143
DescriptionCapstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`, allowing a remote attacker to crash any application using the reduced X86 Capstone library by supplying a crafted input containing the 4-byte sequence `0F 0F <modrm> <imm8>`. Versions 6.0.0-Alpha8 and 5.0.8 patch the issue.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1142678

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
capstone (PTS)bullseye4.0.2-3vulnerable
bookworm4.0.2-5vulnerable
trixie5.0.7-1~deb13u1vulnerable
forky, sid5.0.9-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
capstonesource(unstable)5.0.9-11142678

Notes

[trixie] - capstone <no-dsa> (Minor issue)
[bookworm] - capstone <postponed> (Minor issue)
[bullseye] - capstone <postponed> (Minor issue)
https://github.com/capstone-engine/capstone/security/advisories/GHSA-289w-cm54-fgrm
https://github.com/capstone-engine/capstone/pull/2924
Fixed by: https://github.com/capstone-engine/capstone/commit/fab595205fee206f5c21be6ed8ad2eaf9225f1c7 (5.0.8)

Search for package or bug name: Reporting problems