What is CVE-2026-49282?
A vulnerability (CVE-2026-49282) has been found in the Capstone disassembly framework. Prior to version 6.0.0-Alpha9, the `cs_insn_name()` API forwards caller-supplied instruction IDs to the M68K and RISCV backends without proper validation, potentially leading to information disclosure or denial of service. Users should update to the latest version.
Azərbaycanca: Capstone disassembly framework-də CVE-2026-49282 zəifliyi aşkarlanıb. 6.0.0-Alpha9 əvvəlki versiyalarda `cs_insn_name()` API-si M68K və RISCV backend-lərində daxil olan instruction ID-ləri yoxlamadan istifadə edir. Təsirlənən sistemlərdə bu, məlumat sızmasına və ya xidmət rəddinə səbəb ola bilər, Capstone-u ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
What software is affected by CVE-2026-49282?
The CVE-2026-49282 vulnerability affects the Capstone disassembly framework.
What is recommended to mitigate CVE-2026-49282?
It is recommended to update Capstone to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.