CVE-2025-58447: rAthena has heap-based buffer overflow in login server
rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 2f5248b have a heap-based buffer overflow in the login server, remote attacker to overwrite adjacent session fields by sending a crafted CASSOLOGINREQ with an oversized token length. This leads to immediate denial of service (crash) and it is possible to achieve remote code execution via heap corruption. Commit 2f5248b fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58447?
CVE-2025-58447 has a high severity level due to the heap-based buffer overflow vulnerability.
How do I fix CVE-2025-58447?
To fix CVE-2025-58447, update rAthena to a version later than commit 2f5248b.
What types of attacks can exploit CVE-2025-58447?
CVE-2025-58447 can be exploited by remote attackers to achieve arbitrary code execution via crafted login requests.
Which versions of rAthena are affected by CVE-2025-58447?
All versions of rAthena prior to commit 2f5248b are affected by CVE-2025-58447.
What components of rAthena are impacted by CVE-2025-58447?
The login server component of rAthena is impacted by the buffer overflow vulnerability described in CVE-2025-58447.