{"id":"CVE-2025-15614","summary":"ugrep before 7.6.0 Heap Buffer Over-read via .Z decompression","details":"ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated heap buffer, potentially crashing the process.","modified":"2026-09-06T08:09:19.897851Z","published":"2026-09-05T11:37:59.256Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15614.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15614.json"},{"type":"PACKAGE","url":"https://github.com/Genivia/ugrep"},{"type":"ARTICLE","url":"https://github.com/Genivia/ugrep/blob/v7.5.0/src/zopen.c#L673"},{"type":"FIX","url":"https://github.com/Genivia/ugrep/commit/c12849a11264e2c81c860bf78ee9039772f307a4"},{"type":"REPORT","url":"https://github.com/Genivia/ugrep/issues/511"},{"type":"ADVISORY","url":"https://github.com/Genivia/ugrep/releases/tag/v7.6.0"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-15614"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/ugrep-before-7.6.0-heap-buffer-over-read-via-z-decompression"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/genivia/ugrep","events":[{"introduced":"0"},{"fixed":"c701fb852c8fe5ea48143bf809596470d5e2b248"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"7.6.0"}]}}],"versions":["v7.5.0","v7.4.3","v7.4.2","v7.4.1","v7.4.0","v7.3.0","v7.2.2","v7.2.1","v7.2.0","v7.1.6-(dev)","v7.1.5-(dev)","v7.1.4-(dev)","v7.1.3","v7.1.2","v7.1.1","v7.1.0","v7.0.4","v7.0.3","v7.0.2","v7.0.1","v7.0.0","v6.5.0","v6.4.1","v6.4.0","v6.3.0","v6.2.0","v6.1.0","v6.0.0","v5.1.4","v5.1.3","v5.1.2","v5.1.1","v5.1.0","v5.0.0","v4.5.2","v4.5.1","v4.5.0","v4.4.1","v4.4.0","v4.3.6","v4.3.5","v4.3.4","v4.3.3","v4.3.2","v4.3.1","v4.3.0","v4.2.0","v4.1.0","v4.0.5","v4.0.4","v4.0.3","v4.0.2","v4.0.1","v4.0.0","v3.12.7","v3.12.6","v3.12.5","v3.12.4","v3.12.3","v3.12.2","v3.12.1","v3.12.0","v3.11.2","v3.11.1","v3.11.0","v3.10.1","v3.10.0","v3.9.7","v3.9.6","v3.9.5","v3.9.4","v3.9.3","v3.9.2","v3.9.1","v3.9.0","v3.8.3","v3.8.2","v3.8.1","v3.8.0","v3.7.11","v3.7.10","v3.7.9","v3.7.8","v3.7.7","v3.7.6","v3.7.5","v3.7.4","v3.7.3","v3.7.2","v3.7.1","v3.7.0","v3.6.0","v3.5.0","v3.4.0","v3.3.12","v3.3.11","v3.3.10","v3.3.9","v3.3.8","v3.3.7","v3.3.6","v3.3.5","v3.3.4","v3.3.3","v3.3.2","v3.3.1","v3.3","v3.2.2","v3.2.1","v3.2","v3.1.15","v3.1.14","v3.1.12","v3.1.11","v3.1.10","v3.1.9","v3.1.8","v3.1.7","v3.1.6","v3.1.5","v3.1.4","v3.1.3","v3.1.2","v3.1.1","v3.1.0","v3.0.6","v3.0.5","v3.0.4","v3.0.2","v3.0.1","v3.0.0","v2.5.6","v2.5.5","v2.5.4","v2.5.3","v2.5.2","v2.5.0","v2.4.1","v2.4.0","v2.3.2","v2.3.1","v2.2.1","v2.2.0","v2.1.7","v2.1.4","v2.1.3","v2.1.2","v2.1.1","v2.1.0","v2.0.6","v2.0.4","v2.0.1","v2.0","v1.8.1","v1.8.0","v1.7.10","v1.7.9","v1.7.6","v1.7.5","v1.7.4","v1.7.3","v1.7.2","v1.7.1","v1.6.12","v1.6.10","v1.6.9","v1.6.8","v1.6.7","v1.6.6","v1.6.5","v1.6.3","v1.6.2","v1.6.1","v1.6.0","v1.5.13","1.5.11","v1.5.10","v1.5.8","v1.5.7","v1.5.6","v1.5.4","v1.5.3","v1.5.2","v1.5.0","v1.4.4","v1.4.3","v1.4.2","v1.4.1","v1.4.0","v1.3.8","v1.3.7","v1.3.3","v1.3.2","v1.3.1","v1.2.4","v1.2.2","v1.2.1","v1.1.8","v1.1.6","v1.1.5","v1.1.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15614.json","vanir_signatures_modified":"2026-09-06T08:09:19Z","vanir_signatures":[{"digest":{"function_hash":"14997313270011519701997021847409648442","length":18094},"id":"CVE-2025-15614-1204eef3","signature_type":"Function","signature_version":"v1","source":"https://github.com/genivia/ugrep/commit/c701fb852c8fe5ea48143bf809596470d5e2b248","target":{"file":"src/ugrep.cpp","function":"help"},"deprecated":false},{"target":{"file":"src/ugrep.cpp","function":"init"},"deprecated":false,"digest":{"function_hash":"177419734180137118124790968219898725159","length":23499},"id":"CVE-2025-15614-1a6ba35a","signature_type":"Function","signature_version":"v1","source":"https://github.com/genivia/ugrep/commit/c701fb852c8fe5ea48143bf809596470d5e2b248"},{"digest":{"function_hash":"62273799458531212502393817256537339687","length":51473},"id":"CVE-2025-15614-324519b9","signature_type":"Function","signature_version":"v1","source":"https://github.com/genivia/ugrep/commit/c701fb852c8fe5ea48143bf809596470d5e2b248","target":{"function":"help","file":"src/ugrep.cpp"},"deprecated":false},{"target":{"file":"src/stats.cpp","function":"Stats::report"},"deprecated":false,"digest":{"function_hash":"100512166151003602691001808427697236191","length":6860},"id":"CVE-2025-15614-7edf8cf3","signature_type":"Function","signature_version":"v1","source":"https://github.com/genivia/ugrep/commit/c701fb852c8fe5ea48143bf809596470d5e2b248"},{"target":{"file":"src/ugrep.cpp"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["295365049914243917605725469280414895967","199507004554988354791074811392838330119","268570594253178507224361668448451145601","69816467393306156666112121328704036029","135724568743782686771905149160152014857","221786724283822142769809231464385066225","323621412911053159530212312090357411891","10979523132868959713041954740041362898","68753434050646025497120835939341946911","210383857425728753171839592038978893094","307243415443864920129857473603445234976","146956718825124002001828626905230603577","289576254244014061244354250633829263246","200323294654469853751184986627968507508","309006478599066934430431654842292253595","40556981780232726711662946299044618614","278082575329059116723450939846956601575","210361692630682405142003585253064083884","152806617161726672479081511061053856412","190642055773101292591102529409275182353","76861179978647418201393684887939997654","84444106661701334934531618167585087190","185340804837588800990341227972038098253","188392099933221979549406616019527634862","85738898756730236608180431566522253460","59296139072333609498541408613990973181","180383998377949756562629542583248428948","246764207234959838016736750422781939188","253045007619921715265615849621475917118","42534793180888684372635088591454794465","115483214550314311209227550997994380277","65033355355839144164975673917065837784","200136709552175690927230456679815167982","42534793180888684372635088591454794465","230448448510587962402498223115288020676","192226238392222849865971534012488694191","194069818381891597969547216638972271034","42534793180888684372635088591454794465","198293721354465609421855380815196297491","308764316445994876637024840222167765156","253045007619921715265615849621475917118","42534793180888684372635088591454794465","128995566503883679424478308963717663199","31969671621017982516411433612712083907","309744699337114917205383765345000983984","42534793180888684372635088591454794465","161847342324453493915255748090827485991","209302191541220854435111954084557125284","194069818381891597969547216638972271034","42534793180888684372635088591454794465","319343650843723107599056430503776234113","3836278836431828735453210842431008549","108006004030909801122077417356902385005","178569536254931011812204893304079825260","287704926030900501000688765638284321104","340069398900114469227644076219434499858","30530334383960969099707457275850903904","179299884830072868507795800850832390364","263849220236499726569698384683905194875","21954370850061803161040125081563640624","283401702214975456912117608643038015972","111284693214428409597375830850886272032","95240521832978786805710419005271909488","159176335638237796062115460643716117481","133979905612534514866062621469104245801","133363155074546944936438116634554802174","108535386980119314905875341333990155089","163219162595826519814501413251173615400","145671645267805673277319568647945235273","218141711542142060831792752700095524293","234606337429282838568225078262912197231","35511060835360840834444406669286096017","91668107812217589908927955978617375777","251326530442339785310136715822028748666","4738709558937703496595845012009947701","32349155304239635757878783056391227107","84506106969938188334942020736420451595"]},"id":"CVE-2025-15614-7fb4fb9e","signature_type":"Line","signature_version":"v1","source":"https://github.com/genivia/ugrep/commit/c701fb852c8fe5ea48143bf809596470d5e2b248"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/genivia/ugrep/commit/c701fb852c8fe5ea48143bf809596470d5e2b248","target":{"file":"src/stats.cpp"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["280682208449278407261322454607362368490","262690763136130712905207282567612147125","274869045303738499637732394292931720684","40106919368033180386051964260064147990"]},"id":"CVE-2025-15614-9b0a9cbf"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}