CVE-2025-6141: GNU ncurses parse_entry.c postprocess_termcap stack-based overflow
A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocesstermcap of the file tinfo/parseentry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.
Other sources
GNU ncurses parseentry.c postprocesstermcap stack-based overflow
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GNU ncursesto a version that resolves this vulnerability.Fixed in 6.5-20250329 - Compensating control
Approach the attack as local only (limit exposure so untrusted users/processes cannot execute the vulnerable code path).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6141?
CVE-2025-6141 is classified as problematic and poses a significant risk due to a stack-based buffer overflow.
How do I fix CVE-2025-6141?
To fix CVE-2025-6141, upgrade GNU ncurses to version 6.5-20250323 or later.
Which versions of GNU ncurses are affected by CVE-2025-6141?
CVE-2025-6141 affects GNU ncurses versions up to and including 6.5-20250322.
What type of vulnerability is CVE-2025-6141?
CVE-2025-6141 is a stack-based buffer overflow vulnerability.
What component of GNU ncurses does CVE-2025-6141 impact?
CVE-2025-6141 impacts the function postprocess_termcap in the tinfo/parse_entry.c file.