CVE-2026-100503: Ghidra through 12.1.4 Heap Use-After-Free in Decompiler

Published Sep 26, 2026
·
Updated

Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. Attackers can craft a malicious binary with a specific x86-64 sequence that triggers the vulnerability during decompilation, causing the decompile helper process to crash and denying service to analysts and automated analysis pipelines.

Affected Software

1 affected component
Ghidra Ghidra<=12.1.4

Event History

Sep 26, 2026
CVE Published
via MITRE·12:36 AM
Data Sourced
via MITRE·12:36 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is most likely to be exposed to this issue?

Analysts and automated analysis pipelines that decompile untrusted or attacker-supplied x86-64 binaries are the relevant exposure group. The impact described is denial of service through a crash of the decompile helper process.

2

What does an attacker need to do to trigger the vulnerability?

An attacker needs to provide a malicious binary containing a specific x86-64 instruction sequence and have it processed by Ghidra's decompiler. The attack requires user interaction because the binary must be selected or submitted for decompilation.

3

What can be done if an update cannot be applied immediately?

Avoid decompiling untrusted x86-64 binaries in affected environments, especially in unattended analysis pipelines. Isolate or restrict processing of externally supplied binaries to reduce the opportunity for a crafted input to crash the decompile helper process.

4

How might an affected environment detect exploitation or attempted exploitation?

The observable effect described is a crash of the decompile helper process while decompiling a crafted x86-64 binary. A helper-process crash alone does not establish that this specific vulnerability was triggered.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203