ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.
Published Mar 19, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.45%
Description
The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
Affected products
-
- Version 0StatusaffectedConstraints<6.5-20251213
- Version
- ≤ 6.4
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
No data.
Red Hat Enterprise Linux 10
ncurses-0:6.4-15.20240127.el10_1
Fixed · RHSA-2026:5913
Red Hat Enterprise Linux 10.0 Extended Update Support
ncurses-0:6.4-14.20240127.el10_0.1
Fixed · RHSA-2026:26357
Red Hat Hardened Images
ncurses-main-6.6-1.1.hum1
Fixed · RHSA-2026:7263
Red Hat Enterprise Linux 6
ncurses
Not affected
Red Hat Enterprise Linux 7
ncurses
Not affected
Red Hat Enterprise Linux 8
ncurses
Not affected
Red Hat Enterprise Linux 9
ncurses
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | ncurses-0:6.4-15.20240127.el10_1 | Fixed | RHSA-2026:5913 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | ncurses-0:6.4-14.20240127.el10_0.1 | Fixed | RHSA-2026:26357 |
| Red Hat Hardened Images | ncurses-main-6.6-1.1.hum1 | Fixed | RHSA-2026:7263 |
| Red Hat Enterprise Linux 6 | ncurses | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ncurses | Not affected | n/a |
| Red Hat Enterprise Linux 8 | ncurses | Not affected | n/a |
| Red Hat Enterprise Linux 9 | ncurses | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Moderate impact vulnerability in ncurses affects Red Hat Enterprise Linux 10.0.z and 10.1.z. A buffer overflow in the `analyze_string()` function, exploitable through the `infocmp` utility, could lead to arbitrary code execution. Red Hat Enterprise Linux 6-ELS, 7-ELS, 8.x, 9.x, and OpenShift Container Platform are not affected as the vulnerable code is not present in these versions. Exploitation of this vulnerability requires that an affected application processes malicious data; this requires either user interaction or privileges on an affected system.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
3 other sources (MITRE, CISA ADP, Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Mar 24, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Mar–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.45% (0.00447) | 36.67th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.41% (0.00414) | 32.77th | v5 (v2026.06.15) |
| Mar 20, 2026 | 0.02% (0.00018) | 4.15th | v4 (v2025.03.14) |
References (11)
- https://access.redhat.com/security/cve/CVE-2025-69720 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2449037 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-253495.html
- https://github.com/Cao-Wuhui/CVE-2025-69720 ExploitThird Party Advisory
- https://invisible-island.net/archives/ncurses/6.5/ Release Notes
- https://invisible-island.net/ncurses/ Product
- https://marc.info/?l=ncurses-bug&m=176539968328570&w=2 Issue TrackingMailing ListVendor Advisory
- https://marc.info/?l=ncurses-bug&m=176540731801330&w=2 Issue TrackingMailing ListVendor Advisory
- https://marc.info/?l=ncurses-bug&m=176545557728083&w=2 Issue TrackingMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-69720
- https://www.cve.org/CVERecord?id=CVE-2025-69720
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-69720 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2449037 | Issue Tracking | |
| https://cert-portal.siemens.com/productcert/html/ssa-253495.html | ||
| https://github.com/Cao-Wuhui/CVE-2025-69720 | ExploitThird Party Advisory | |
| https://invisible-island.net/archives/ncurses/6.5/ | Release Notes | |
| https://invisible-island.net/ncurses/ | Product | |
| https://marc.info/?l=ncurses-bug&m=176539968328570&w=2 | Issue TrackingMailing ListVendor Advisory | |
| https://marc.info/?l=ncurses-bug&m=176540731801330&w=2 | Issue TrackingMailing ListVendor Advisory | |
| https://marc.info/?l=ncurses-bug&m=176545557728083&w=2 | Issue TrackingMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-69720 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-69720 |
Change history (0)
No recorded changes yet.