{"id":"CVE-2026-45612","summary":"rz-libdemangle: Out of bound read in rust demangler","details":"rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can perform an out-of-bounds read when the demangler structure is not yet initialized. This issue is fixed in commit 6bf56d3.","aliases":["GHSA-4p92-mfjf-qvrc"],"modified":"2026-07-22T04:18:39.581103Z","published":"2026-07-16T16:34:40.398Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45612.json","unresolved_ranges":[{"extracted_events":[{"fixed":"6bf56d32b32547ae4cb069ccfc2d2b6c7b63a4cb"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-125"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45612.json"},{"type":"ADVISORY","url":"https://github.com/rizinorg/rz-libdemangle/security/advisories/GHSA-4p92-mfjf-qvrc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45612"},{"type":"FIX","url":"https://github.com/rizinorg/rz-libdemangle/commit/6bf56d32b32547ae4cb069ccfc2d2b6c7b63a4cb"},{"type":"FIX","url":"https://github.com/rizinorg/rz-libdemangle/pull/83"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rizinorg/rz-libdemangle","events":[{"introduced":"0"},{"fixed":"6bf56d32b32547ae4cb069ccfc2d2b6c7b63a4cb"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"vanir_signatures_modified":"2026-07-22T04:18:39Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/rizinorg/rz-libdemangle/commit/6bf56d32b32547ae4cb069ccfc2d2b6c7b63a4cb","target":{"file":"src/rust/rust_v0.c","function":"rust_v0_init"},"deprecated":false,"digest":{"function_hash":"130256863017545106152075704784632960263","length":532},"id":"CVE-2026-45612-2242b214"},{"deprecated":false,"digest":{"line_hashes":["210621266899617050114883449507934937972","192011128218880355152452380997428338676","89968753629804683755547767688945628739","35825315609863217398715222015073202717","314965882478240891506672545863456576088","306467788505251560686826169826681570385","300148913813221087188491417619024435873"],"threshold":0.9},"id":"CVE-2026-45612-f16b7a6d","signature_type":"Line","signature_version":"v1","source":"https://github.com/rizinorg/rz-libdemangle/commit/6bf56d32b32547ae4cb069ccfc2d2b6c7b63a4cb","target":{"file":"src/rust/rust_v0.c"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45612.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}