CVE-2025-49589: PCSX2 Contains a Stack-based Buffer Overflow in IOP Console Logging
Published Jun 12, 2025
·Updated
PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. A stack-based buffer overflow exists in the KprintfHLE function of PCSX2 versions up to 2.3.414. Opening a disc image that logs a specially crafted message may allow a remote attacker to execute arbitrary code if the user enabled IOP Console Logging. This vulnerability is fixed in 2.3.414.
Affected Software
1 affected component
PCSX2 PCSX2<=2.3.414
Event History
Jun 12, 2025
CVE Published
via MITRE·08:56 PM
Data Sourced
via MITRE·08:56 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
May 20, 57433
Event
via FIRST·11:11 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-49589?
CVE-2025-49589 has a high severity due to the potential for arbitrary code execution.
2
How do I fix CVE-2025-49589?
To fix CVE-2025-49589, update PCSX2 to version 2.3.415 or later.
3
What type of vulnerability is CVE-2025-49589?
CVE-2025-49589 is a stack-based buffer overflow vulnerability.
4
Who is affected by CVE-2025-49589?
PCSX2 versions up to 2.3.414 are affected by CVE-2025-49589.
5
What can an attacker do with CVE-2025-49589?
An attacker can potentially execute arbitrary code on a victim's system by exploiting CVE-2025-49589.