A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to…
High CVSS 7.0
Summary
A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Lint boundary warnings (1)
The following non-blocking warnings were raised during the lint phase of this triage (e.g. reference URLs not yet on the allowlist). They do not affect entry usability and are disclosed for transparency (see DR-002).
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://unicode-org.atlassian.net/jira/software/c/projects/ICU/issues/ICU-22957
Sources
- NVD DATABASE
Original Links
- https://access.redhat.com/errata/RHSA-2025:11888 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2025:12083 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2025:12331 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2025:12332 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2025:12333 Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2025-5222 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2368600 Issue Tracking
- https://unicode-org.atlassian.net/jira/software/c/projects/ICU/issues/ICU-22957
- https://lists.debian.org/debian-lts-announce/2025/06/msg00015.html Mailing List
- https://cert-portal.siemens.com/productcert/html/ssa-585531.html
- https://access.redhat.com/errata/RHSA-2026:54581
Timeline
- nvd_ingest NVD