# CVE-2025-68114

## Summary

- **CVE ID:** CVE-2025-68114
- **Severity:** MEDIUM
- **CVSS Score:** 4.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
- **CWE:** CWE-124, CWE-120
- **Published:** Dec 17, 2025
- **Last Modified:** Mar 13, 2026

## Description

Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a1618be12017d7d41e0b6581d5d529e fixes the issue.

## Affected Products

- capstone-engine — capstone (<= 6.0.0-Alpha5)

## References

- [CNA](https://github.com/capstone-engine/capstone/security/advisories/GHSA-85f5-6xr3-q76r)
- [CNA](https://github.com/capstone-engine/capstone/commit/2c7797182a1618be12017d7d41e0b6581d5d529e)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 9.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._