Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecode
Published Aug 20, 2026
7.3
HIGHCVSS 4.0
EPSS 0.19%
Description
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without checking the fixed-size operands[] array. Repeated crafted instructions processed through cs_disasm_iter() or cs_disasm() with CS_ARCH_SH, CS_MODE_SH2A or CS_MODE_SH4A, CS_MODE_SHFPU, and CS_OPT_DETAIL can increment the operand count beyond the 176-byte sh_info allocation and perform a four-byte heap buffer overflow write. The corruption can crash the process and may enable code execution depending on heap layout. This issue is fixed in version 6.0.0-Alpha10.
Affected products
-
- Version < 6.0.0-Alpha10StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Capstone-Engine | Capstone | n/a |
|
No data.
No data.
Red Hat Hardened Images
capstone-main-5.0.8-0.3.hum1
Fixed · RHSA-2026:59419
Red Hat Enterprise Linux 10
capstone
Affected
Red Hat Enterprise Linux 9
capstone
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | capstone-main-5.0.8-0.3.hum1 | Fixed | RHSA-2026:59419 |
| Red Hat Enterprise Linux 10 | capstone | Affected | n/a |
| Red Hat Enterprise Linux 9 | capstone | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Aug 21, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.19% (0.00186) | 7.40th | v5 (v2026.06.15) |
| Aug 21, 2026 | 0.14% (0.00142) | 4.02th | v5 (v2026.06.15) |
References (10)
- https://access.redhat.com/security/cve/CVE-2026-55893 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2520815 Issue Tracking
- https://github.com/capstone-engine/capstone/commit/09e76802380b9e94d9720c44458d9d5282219e7e x_refsource_MISC
- https://github.com/capstone-engine/capstone/commit/e17ee44a8307ea33375b4727ac4f987650bf7bed x_refsource_MISC
- https://github.com/capstone-engine/capstone/pull/2968 x_refsource_MISC
- https://github.com/capstone-engine/capstone/pull/2969 x_refsource_MISC
- https://github.com/capstone-engine/capstone/releases/tag/6.0.0-Alpha10 x_refsource_MISC
- https://github.com/capstone-engine/capstone/security/advisories/GHSA-3hpv-wr3j-rxwh x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-55893
- https://www.cve.org/CVERecord?id=CVE-2026-55893
Change history (0)
No recorded changes yet.