CVE-2025-8736: GNU cflow Lexer c.c yylex buffer overflow
Published Aug 8, 2025
·Updated
A vulnerability, which was classified as critical, has been found in GNU cflow up to 1.8. Affected by this issue is the function yylex of the file c.c of the component Lexer. The manipulation leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
GNU cflow<=1.8
Event History
Aug 8, 2025
CVE Published
via MITRE·07:02 PM
Data Sourced
via MITRE·07:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Jun 23, 58473
Event
via NVD·04:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-8736?
CVE-2025-8736 is classified as a critical vulnerability.
2
How do I fix CVE-2025-8736?
To fix CVE-2025-8736, update GNU cflow to version 1.9 or later.
3
What type of vulnerability is CVE-2025-8736?
CVE-2025-8736 is a buffer overflow vulnerability affecting the Lexer component.
4
What software is affected by CVE-2025-8736?
GNU cflow versions up to and including 1.8 are affected by CVE-2025-8736.
5
Is local access required to exploit CVE-2025-8736?
Yes, local access is required to exploit the CVE-2025-8736 vulnerability.