CVE-2025-9301: cmake cmForEachCommand.cxx ReplayItems assertion
A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::ReplayItems of the file cmForEachCommand.cxx. This manipulation causes reachable assertion. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. Patch name: 37e27f71bc356d880c908040cd0cb68fa2c371b8. It is suggested to install a patch to address this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9301?
CVE-2025-9301 has a severity that indicates it can lead to a local denial of service due to reachable assertions in CMake.
How do I fix CVE-2025-9301?
To fix CVE-2025-9301, you should update to a patched version of CMake released by Kitware.
Who is affected by CVE-2025-9301?
CVE-2025-9301 affects users of CMake version 4.1.20250725-gb5cce23.
Can CVE-2025-9301 be exploited remotely?
CVE-2025-9301 requires a local exploit, meaning it cannot be exploited remotely without local access.
What component of CMake does CVE-2025-9301 affect?
CVE-2025-9301 affects the cmForEachFunctionBlocker::ReplayItems function in the cmForEachCommand.cxx file.