Logo
vulnerabilityCVE-2025-9301
Name
CVE-2025-9301
Source
NVD ( link)Debian ( link)
Description
A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::ReplayItems of the file cmForEachCommand.cxx. This manipulation causes reachable assertion. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. Patch name: 37e27f71bc356d880c908040cd0cb68fa2c371b8. It is suggested to install a patch to address this issue.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
cmake
Patched

Vulnerability Ratings#


1.9
CVSSv4
3.3
CVSSv31
1.7
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.31.12
Not Affected
buildroot
master
4.3.4
Not Affected
yocto
kirkstone
3.22.3
Patched
yocto
master
4.3.3
Not Affected

Resolved with patches#


cmake (yocto:kirkstone)

#
Title
Author
Resolve
1
foreach: Explicitly skip replay without iterations
Tyler Yankee <tyler.yankee@kitware.com>
CVE-2025-9301

cmake (yocto:scarthgap)

#
Title
Author
Resolve
1
foreach: Explicitly skip replay without iterations
Tyler Yankee <tyler.yankee@kitware.com>
CVE-2025-9301