Logo
vulnerabilityCVE-2025-5222
Name
CVE-2025-5222
Source
NVD ( link)Debian ( link)
Description
A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
icu
Patched

Vulnerability Ratings#


7
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
73-2
Exploitable
buildroot
master
78.2
Not Affected
openwrt
master
78.3-r1
Not Affected
openwrt
openwrt-25.12
78.2-r1
Not Affected
yocto
master
78.3
Not Affected
yocto
scarthgap
74-2
Patched

Resolved with patches#


icu (yocto:kirkstone)

#
Title
Author
Resolve
1
ICU-22973 Fix buffer overflow by using CharString
Frank Tang <ftang@chromium.org>
CVE-2025-5222

icu (yocto:scarthgap)

#
Title
Author
Resolve
1
ICU-22973 Fix buffer overflow by using CharString
Frank Tang <ftang@chromium.org>
CVE-2025-5222