{"apiVersion":"1.0","identifier":"CVE-2026-49282","description":"Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone-s public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID before indexing instruction-name tables, but the M68K and RISCV backends have missing or incomplete bounds checks. On a Capstone handle opened for M68K or RISCV, a caller-controlled invalid instruction ID can trigger an out-of-bounds read and crash the process. The demonstrated impact is availability loss in applications or bindings that expose instruction-name lookup to untrusted IDs. No code execution or data disclosure was demonstrated. Version 6.0.0-Alpha9 patches the issue.","publishedAt":"2026-08-14T18:17:30","lastModifiedAt":"2026-08-17T19:16:31","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-49282","cvssScore":5.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","epssProbability":0.00132,"riskScore":0.52,"affectedProduct":"Capstone","affectedVersions":"<6.0.0-Alpha9","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-49282","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-49282","en":"https://www.redsauce.net/en/cves/CVE-2026-49282","fr":"https://www.redsauce.net/fr/cves/CVE-2026-49282","pt":"https://www.redsauce.net/pt/cves/CVE-2026-49282","de":"https://www.redsauce.net/de/cves/CVE-2026-49282","sk":"https://www.redsauce.net/sk/cves/CVE-2026-49282","el":"https://www.redsauce.net/el/cves/CVE-2026-49282"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-49282"}}