Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 10 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function during the variable merging pass. Attackers can trigger this vulnerability by crafting a binary that causes stale pointers in the HighIntersectTest::highedgemap cache to be dereferenced, reading and writing the flags field of freed heap memory when a user opens the binary in Ghidra's decompiler view. | |
| Title | Ghidra < 12.1 - Heap-use-after-free in HighVariable::merge() during decompilation | |
| First Time appeared |
Nsa
Nsa ghidra |
|
| Weaknesses | CWE-416 | |
| CPEs | cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nsa
Nsa ghidra |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-10T16:31:45.453Z
Reserved: 2026-06-08T15:20:09.274Z
Link: CVE-2026-52757
Updated: 2026-06-10T16:20:09.075Z
Status : Analyzed
Published: 2026-06-10T14:16:36.027
Modified: 2026-06-12T01:10:23.797
Link: CVE-2026-52757
No data.
OpenCVE Enrichment
Updated: 2026-06-11T10:42:05Z