CVE-2025-8735: GNU cflow Lexer c.c yylex null pointer dereference
Published Aug 8, 2025
·Updated
A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the function yylex of the file c.c of the component Lexer. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
GNU cflow<=1.8
Event History
Aug 8, 2025
CVE Published
via MITRE·06:32 PM
Data Sourced
via MITRE·06:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Jun 17, 58473
Event
via NVD·11:57 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-8735?
CVE-2025-8735 is classified as a problematic vulnerability.
2
How do I fix CVE-2025-8735?
To mitigate CVE-2025-8735, upgrade GNU cflow to a version greater than 1.8.
3
What type of issue is CVE-2025-8735 related to?
CVE-2025-8735 is related to a null pointer dereference in the Lexer component.
4
Is CVE-2025-8735 exploitable remotely?
No, CVE-2025-8735 requires local access to exploit.
5
Which versions of GNU cflow are affected by CVE-2025-8735?
GNU cflow versions up to and including 1.8 are affected by CVE-2025-8735.