CVE-2026-100504 HIGH

CVE-2026-100504: Ghidra through 12.1.4 Stack-based Buffer Overflow via leftshift128

Vendor Nationalsecurityagency
Product ghidra
Weakness CWE-787
Published September 26, 2026
Last update September 26, 2026

CVSS base score

7.3/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. Attackers can craft malicious binaries with specific instruction sequences that trigger the overflow when decompiled, corrupting memory and potentially achieving code execution.

Key dates

02Disclosure timeline

September 26, 2026 CVE published