{"id":"CVE-2023-27590","summary":"Rizin has stack-based buffer overflow when parsing GDB registers profile files","details":"Rizin is a UNIX-like reverse engineering framework and command-line toolset. In version 0.5.1 and prior, converting a GDB registers profile file into a Rizin register profile can result in a stack-based buffer overflow when the `name`, `type`, or `groups` fields have longer values than expected. Users opening untrusted GDB registers files (e.g. with the `drpg` or `arpg` commands) are affected by this flaw. Commit d6196703d89c84467b600ba2692534579dc25ed4 contains a patch for this issue. As a workaround, review the GDB register profiles before loading them with `drpg`/`arpg` commands.","aliases":["GHSA-rqcp-m8m2-jcqf"],"modified":"2026-08-12T13:34:04.378511Z","published":"2023-03-14T20:37:59.269Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-120","CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/27xxx/CVE-2023-27590.json"},"references":[{"type":"WEB","url":"https://github.com/rizinorg/rizin/blob/3a7d5116244beb678ad9950bb9dd27d28ed2691f/librz/reg/profile.c#L514"},{"type":"WEB","url":"https://github.com/rizinorg/rizin/blob/3a7d5116244beb678ad9950bb9dd27d28ed2691f/librz/reg/profile.c#L545"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WW3JXI4TIJIR7PGFP74SN7GQYHW2F46Y/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/27xxx/CVE-2023-27590.json"},{"type":"ADVISORY","url":"https://github.com/rizinorg/rizin/security/advisories/GHSA-rqcp-m8m2-jcqf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-27590"},{"type":"FIX","url":"https://github.com/rizinorg/rizin/commit/d6196703d89c84467b600ba2692534579dc25ed4"},{"type":"FIX","url":"https://github.com/rizinorg/rizin/pull/3422"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rizinorg/rizin","events":[{"introduced":"0"},{"fixed":"d6196703d89c84467b600ba2692534579dc25ed4"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:rizin:rizin:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.5.1"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-27590.json","vanir_signatures_modified":"2026-08-12T13:34:04Z","vanir_signatures":[{"target":{"function":"rz_debug_gdb_map_get","file":"librz/debug/p/debug_gdb.c"},"deprecated":false,"digest":{"function_hash":"18607978036642143582711138346563480936","length":2879},"id":"CVE-2023-27590-4d41dff8","signature_type":"Function","signature_version":"v1","source":"https://github.com/rizinorg/rizin/commit/d6196703d89c84467b600ba2692534579dc25ed4"},{"id":"CVE-2023-27590-67381ffa","signature_type":"Function","signature_version":"v1","source":"https://github.com/rizinorg/rizin/commit/d6196703d89c84467b600ba2692534579dc25ed4","target":{"file":"librz/reg/profile.c","function":"gdb_to_rz_profile"},"deprecated":false,"digest":{"function_hash":"74621615392222976525878869266564975266","length":2211}},{"digest":{"line_hashes":["175254883242477449917601869919524210768","174225006671969015886447125363474126297","257506788415765286171109721175300323318","58803747756217229094191292083929280545","236804163066184189160741118571722553733","292967053446417490973497143198006587788","64545973321600873150238841391001433184","49105148134911982257882221308519699524","282492726561145555332747843848833691552","53409029844906465446048310450689681814","295378834024531363987587621827006517387","140994653325765102470017657054478478627"],"threshold":0.9},"id":"CVE-2023-27590-85994458","signature_type":"Line","signature_version":"v1","source":"https://github.com/rizinorg/rizin/commit/d6196703d89c84467b600ba2692534579dc25ed4","target":{"file":"librz/reg/profile.c"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/rizinorg/rizin/commit/d6196703d89c84467b600ba2692534579dc25ed4","target":{"file":"librz/debug/p/debug_io.c","function":"__io_maps"},"deprecated":false,"digest":{"function_hash":"95053583293763907149763148861760122041","length":1016},"id":"CVE-2023-27590-8f5cdc9d","signature_type":"Function"},{"target":{"file":"librz/debug/p/debug_gdb.c"},"deprecated":false,"digest":{"line_hashes":["208399971039770271019143947541657333566","250696370723515248091592113580293315279","218244030341975531012960145768966983572","2113860878183312366453466714998493729","214247743934078689277601440308942560670","5611799406701412293718049641770857687","1735741582096301764266395183239186599","135114330681930923966664161456663713014","235541441784038319814582722930510795854","10626561024625739049338930036693896222","50010599365793608052325724292379589264","14309896032952564393871344222887408943"],"threshold":0.9},"id":"CVE-2023-27590-a16e5a74","signature_type":"Line","signature_version":"v1","source":"https://github.com/rizinorg/rizin/commit/d6196703d89c84467b600ba2692534579dc25ed4"},{"id":"CVE-2023-27590-cf0678ea","signature_type":"Line","signature_version":"v1","source":"https://github.com/rizinorg/rizin/commit/d6196703d89c84467b600ba2692534579dc25ed4","target":{"file":"librz/debug/p/debug_io.c"},"deprecated":false,"digest":{"line_hashes":["312842880064489064432466741478329028665","333643235589225623569731629921795632890","143963744419464870724574926358981445029","314932442725368578022782592203988864710","292114020763624109107827564800657965564","167411720492855813614563629399990612833","261137153026207221653131574541026187510","81442484958557519021535605873545238609","105225277461659746839416559576230580982","276308943640951893977876076719999997560","198311630489627096174608925769220067874"],"threshold":0.9}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}