CVE-2026-100503
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 08:15
Description
Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. Attackers can craft a malicious binary with a specific x86-64 sequence that triggers the vulnerability during decompilation, causing the decompile helper process to crash and denying service to analysts and automated analysis pipelines.
Aliases and classifications
Minimised technical details
No raw data- cisa kev
- False
- cvss score
- 3.3
- cvss vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
- cvss severity
- LOW
Public references
- technical-description
https://github.com/NationalSecurityAgency/ghidra/blob/8b6bbb857accdfa20dc5b2f5dea471178c2e9fbc/Ghidra/Features/Decompiler/src/decompile/cpp/merge.cc - Product Repository
https://github.com/NationalSecurityAgency/ghidra - Patch Commit
https://github.com/NationalSecurityAgency/ghidra/commit/5ef1ee4d7a25a65db195f3a70f681ca74440be61 - VulnCheck Advisory: Ghidra through 12.1.4 Heap Use-After-Free in Decompiler
https://www.vulncheck.com/advisories/ghidra-through-12.1.4-heap-use-after-free-in-decompiler - technical-description
https://github.com/NationalSecurityAgency/ghidra/blob/8b6bbb857accdfa20dc5b2f5dea471178c2e9fbc/Ghidra/Features/Decompiler/src/decompile/cpp/subflow.cc
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.