CVE-2026-49497: Ghidra < 12.1 - Path Traversal via .gnu_debuglink in DWARF External Debug File Resolution
Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnudebuglink sections before constructing file paths. Attackers can craft malicious ELF binaries with traversal sequences to probe filesystem existence and leak CRC32 hashes of arbitrary files during automatic DWARF analysis.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghidrato a version that resolves this vulnerability.Fixed in 12.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49497?
The severity of CVE-2026-49497 is rated as medium with a score of 4.6.
How do I fix CVE-2026-49497?
To fix CVE-2026-49497, update Ghidra to version 12.1 or later, where the vulnerability has been resolved.
What systems are affected by CVE-2026-49497?
CVE-2026-49497 affects all versions of Ghidra prior to 12.1.
What type of vulnerability is CVE-2026-49497?
CVE-2026-49497 is classified as a path traversal vulnerability.
What can attackers achieve using CVE-2026-49497?
Attackers can exploit CVE-2026-49497 to craft malicious ELF binaries that leak sensitive filesystem information.