Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-5222

24
FAUCET Score

CVE-2025-5222 describes a stack buffer overflow in International Components for Unicode (ICU) that occurs when processing the 'subtag' struct within the genrb binary's SRBRoot::addTag function. This vulnerability, affecting unicode international_components_for_unicode, carries a high severity CVSS score of 7.0, indicating a local attack vector with high attack complexity, requiring user interaction, and potentially leading to memory corruption and local arbitrary code execution. Currently, there is no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and minimal community discussion, with the vulnerability not listed in CISA's KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
< 77.1CPE matchmatch criteria
cpe:2.3:a:unicode:international_components_for_unicode:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.0HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 12th percentile among its peer group of 386 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (19)

microsoftpatch availablevia msrc
Product: azl3 nodejs 20.14.0-9 on Azure Linux 3.0Fixed in: 20.14.0-10
microsoftpatch availablevia msrc
Product: 19571-16823Fixed in: 68.2.0.9-2
microsoftpatch availablevia msrc
Product: 20162-17086Fixed in: 68.2.0.9-2
microsoftpatch availablevia msrc
Product: 20165-17084Fixed in: 72.1.0.3-2
microsoftpatch availablevia msrc
Product: 20367-17086Fixed in: 18.20.3-10
microsoftpatch availablevia msrc
Product: 19904-17084Fixed in: 20.14.0-10
microsoftpatch availablevia msrc
Product: cbl2 icu 68.2.0.9-2 on CBL Mariner 2.0Fixed in: 68.2.0.9-2
microsoftpatch availablevia msrc
Product: cbl2 icu 68.2.0.9-1 on CBL Mariner 2.0Fixed in: 68.2.0.9-2
microsoftpatch availablevia msrc
Product: azl3 icu 72.1.0.3-2 on Azure Linux 3.0Fixed in: 72.1.0.3-2
microsoftpatch availablevia msrc
Product: cbl2 nodejs18 18.20.3-9 on CBL Mariner 2.0Fixed in: 18.20.3-10
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: icu-0:67.1-10.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: icu-0:67.1-10.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: icu-0:67.1-10.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: icu-0:67.1-10.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: icu-0:74.2-5.el10_0
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: mingw-icu
redhatvendor investigatingvia nvd_reference
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: icu
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos

Vendor Advisories (2)

microsoft2025-May/CVE-2025-5222Important

Icu: stack buffer overflow in the srbroot::addtag function

May 13, 2025
redhatCVE-2025-5222Moderate

icu: Stack buffer overflow in the SRBRoot::addTag function

Nov 14, 2024

References

cert-portal.siemens.com / productcert/html/ssa-585531.html
lists.debian.org / debian-lts-announce/2025/06/msg00015.html
Mailing List
access.redhat.com / errata/RHSA-2025:11888
Vendor Advisory
access.redhat.com / errata/RHSA-2025:12083
Vendor Advisory
access.redhat.com / errata/RHSA-2025:12331
Vendor Advisory
access.redhat.com / errata/RHSA-2025:12332
Vendor Advisory
access.redhat.com / errata/RHSA-2025:12333
Vendor Advisory
access.redhat.com / security/cve/CVE-2025-5222
Vendor Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
unicode-org.atlassian.net / jira/software/c/projects/ICU/issues/ICU-22957