MEDIUM
capstone-engine
CVE published 2026-07-21
CVE-2026-47143
A NULL pointer dereference vulnerability exists in the Capstone disassembly framework, affecting versions prior to 6.0.0-Alpha8 and 5.0.8. The vulnerability occurs in the `modRMRequired()` and `decode()` functions when disassembling 3DNow! opcodes (`0F 0F`). A remote attacker can crash any application using the reduced X86 Capstone library by supplying a crafted input containing the 4-byte sequence `0F 0F [truncated]