Executive brief
Capstone is a disassembly framework used by binary analysis tools and security software to interpret machine code. A flaw in its SH (SuperH) architecture decoder allows malicious or malformed bytecode to trigger an out-of-bounds memory read, crashing the application. While no code execution occurs, this denial-of-service impact could interrupt critical analysis workflows or be chained with other vulnerabilities.
Technical details
The vulnerability is an out-of-bounds read in arch/SH/SHDisassembler.c's sh_disassemble() function. When processing crafted 16-bit SH instructions with architectures CS_MODE_SH2A, CS_MODE_SH4A, or CS_MODE_SHFPU, the function computes an idx value from the instruction without validating that it falls within the bounds of the mode-specific decode[] function-pointer table. An attacker can pass malicious bytecode via cs_disasm_iter() or cs_disasm() to trigger an out-of-bounds access and cause a segmentation fault, denying service to the application. No information disclosure or code execution was demonstrated. The fix was released in version 6.0.0-Alpha10 and backported to the v5 branch.
Affected products
- Capstone Capstone 6.0.0-Alpha9 and earlier
Timeline
- 2026-08-20: disclosed: Published on NVD
- 2026-06-18: patched: Fixed in version 6.0.0-Alpha10 and v5 branch