-Infinity
0

Vendor Risk Score

See how upx compares to other vendors in security performance

View Risk Score →

Software

Severity
9.8
EPSS
0.04%
Buffer Overflow
AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function getne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259055. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

First published (updated )
Severity
5.5
EPSS
0.01%
Buffer Overflow
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

A vulnerability, which was classified as problematic, was found in UPX up to 5.0.0. Affected is the function PackLinuxElf64::unDTINIT of the file src/plxelf.cpp. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The patch is identified as e0b6ff192412f5bb5364c1948f4f6b27a0cd5ea2. It is recommended to apply a patch to fix this issue.

First published (updated )
Severity
4

A Segmentation fault was found in UPX in invertptdynamic() function in plxelf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.

https://github.com/upx/upx/issues/631 https://github.com/upx/upx/commit/779b648c5f6aa9b33f4728f79dd4d0efec0bf860

First published (updated )
Severity
4

An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.1. The flow allows attackers to cause a denial of service (abort) via a crafted file.

https://github.com/upx/upx/issues/632 https://github.com/upx/upx/commit/510505a85cbe45e51fbd470f1aa8b02157c429d4

First published (updated )
Severity
4
Null Pointer Dereference

Null pointer dereference was found in upx PackLinuxElf::canUnpack() in plxelf.cpp,in version UPX 4.0.0. That allow attackers to execute arbitrary code and cause a denial of service via a crafted file.

Upstream issue:

https://github.com/upx/upx/issues/48

Upstream patch:

https://github.com/upx/upx/commit/90279abdfcd235172eab99651043051188938dcc

First published (updated )
Severity
1

An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abort) via a crafted file.

Upstream issue:

https://github.com/upx/upx/issues/486

Upstream patch: https://github.com/upx/upx/pull/487 https://github.com/upx/upx/commit/28e761cd42211dfe0124b7a29b2f74730f453e46

First published (updated )
Severity
1
Buffer Overflow

A flaw was found in upx canPack in plxelf.cpp in UPX 3.96 that allows attackers to cause a denial of service (SEGV or buffer overflow, and application crash) or possibly have unspecified other impacts via a crafted ELF.

Upstream issue:

https://github.com/upx/upx/issues/421

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203