Junglewise Threat Intelligence

CVE-2026-55894: Capstone SH disassembler out-of-bounds read

CVE-2026-55894 · Severity: info · Published 2026-08-20

Technologies: Capstone.

Executive brief

Capstone is a disassembly framework used by binary analysis tools and security software to interpret machine code. A flaw in its SH (SuperH) architecture decoder allows malicious or malformed bytecode to trigger an out-of-bounds memory read, crashing the application. While no code execution occurs, this denial-of-service impact could interrupt critical analysis workflows or be chained with other vulnerabilities.

Technical details

The vulnerability is an out-of-bounds read in arch/SH/SHDisassembler.c's sh_disassemble() function. When processing crafted 16-bit SH instructions with architectures CS_MODE_SH2A, CS_MODE_SH4A, or CS_MODE_SHFPU, the function computes an idx value from the instruction without validating that it falls within the bounds of the mode-specific decode[] function-pointer table. An attacker can pass malicious bytecode via cs_disasm_iter() or cs_disasm() to trigger an out-of-bounds access and cause a segmentation fault, denying service to the application. No information disclosure or code execution was demonstrated. The fix was released in version 6.0.0-Alpha10 and backported to the v5 branch.

Affected products

  • Capstone Capstone 6.0.0-Alpha9 and earlier

Timeline

  • 2026-08-20: disclosed: Published on NVD
  • 2026-06-18: patched: Fixed in version 6.0.0-Alpha10 and v5 branch

References