{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-100504/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7,"id":"CVE-2026-100504"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ghidra (\u003c= 12.1.4)"],"_cs_severities":["high"],"_cs_tags":["cve-2026-100504","memory-corruption","software-vulnerability"],"_cs_type":"advisory","_cs_vendors":["National Security Agency"],"content_html":"\u003cp\u003eGhidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability located in the decompiler's leftshift128 function. This vulnerability is triggered when the decompiler processes p-code containing negative shift amounts. An attacker can exploit this by providing a specially crafted binary containing specific instruction sequences. When a user opens or performs analysis on this malicious binary within Ghidra, the decompiler's memory becomes corrupted during the calculation process. This memory corruption can lead to the execution of arbitrary code with the privileges of the user running the Ghidra application. This is particularly relevant for security researchers and reverse engineers who frequently analyze untrusted binaries.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to the security research community and software analysts who use Ghidra for reverse engineering tasks. If exploited, an attacker could gain control over the analyst's machine, potentially leading to the theft of sensitive project data, intellectual property, or further lateral movement within an organization's network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and inventory all instances of Ghidra 12.1.4 or earlier within the development and research environments.\u003c/li\u003e\n\u003cli\u003eUpgrade all instances of Ghidra to the latest patched version available from the official National Security Agency repository.\u003c/li\u003e\n\u003cli\u003eImplement a policy to sandbox reverse engineering tools, including Ghidra, to minimize the impact of potential arbitrary code execution vulnerabilities.\u003c/li\u003e\n\u003cli\u003eAlert users who frequently analyze third-party or untrusted binaries to be cautious when importing unknown files into the Ghidra environment until patches are applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T02:55:34Z","date_published":"2026-09-26T02:55:34Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ghidra-oob-write/","summary":"Ghidra versions 12.1.4 and earlier contain a stack-based out-of-bounds write vulnerability in the leftshift128 function that could allow arbitrary code execution when processing malicious binaries.","title":"Stack-Based Out-of-Bounds Write in Ghidra Decompiler","url":"https://feed.craftedsignal.io/briefs/2026-09-ghidra-oob-write/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-100504","version":"https://jsonfeed.org/version/1.1"}