Junglewise Threat Intelligence

CVE-2025-12829: Amazon Ion-C uninitialized stack read in data serialization

CVE-2025-12829 · Severity: high · Published 2025-11-07

Technologies: Amazon AWS. Vendors: Amazon.

Executive brief

Amazon Ion-C is a software library used by developers to process and exchange data in the Amazon Ion format. A security flaw in this library could allow an attacker to send specially crafted data that tricks the system into revealing sensitive information stored in the computer's memory. This could lead to the exposure of private data or credentials to unauthorized parties.

Technical details

An uninitialized stack read vulnerability exists in Amazon Ion-C versions prior to v1.1.4. The flaw occurs during the serialization of Ion data to text format. A threat actor can provide specially crafted input that, when processed, causes the library to read uninitialized memory from the stack and include it in the output as UTF-8 escape sequences. This can lead to the disclosure of sensitive information residing in the application's memory space. The issue is resolved in Ion-C version 1.1.4.

Affected products

  • Amazon Ion-C < v1.1.4

Timeline

  • 2025-11-07: disclosed
  • 2025-11-07: patched: Fixed in version 1.1.4

References

Related threats