CVE-2025-8736

Name
CVE-2025-8736
Description
A vulnerability, which was classified as critical, has been found in GNU cflow up to 1.8. Affected by this issue is the function yylex of the file c.c of the component Lexer. The manipulation leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
exploit https://drive.google.com/file/d/17lkJ5bSiQZoXLTg3bK-rGBt3kahN9Xse/view?usp=drive_link
related https://lists.gnu.org/archive/html/bug-cflow/2025-07/msg00001.html
signature https://vuldb.com/?ctiid.319232
vdb-entry https://vuldb.com/?id.319232
third-party-advisory https://vuldb.com/?submit.622329
product https://www.gnu.org/

Match rules

CPE URI Source package Min version Max version
cflow == 1.0 == 1.0
cflow == 1.1 == 1.1
cflow == 1.2 == 1.2
cflow == 1.3 == 1.3
cflow == 1.4 == 1.4
cflow == 1.5 == 1.5
cflow == 1.6 == 1.6
cflow == 1.7 == 1.7
cflow == 1.8 == 1.8

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
cflow edge-community 1.8-r0 qaqland <qaq@qaq.land> possibly vulnerable
cflow edge-community 1.7-r1 qaqland <qaq@qaq.land> possibly vulnerable
cflow edge-community 1.7-r0 qaqland <qaq@qaq.land> possibly vulnerable
cflow 3.22-community 1.7-r0 qaqland <qaq@qaq.land> possibly vulnerable