CVE-2025-8746 is a memory corruption vulnerability in the __strstr_sse2 function of GNU libopts, affecting products that utilize this external library and are no longer supported by their maintainers. This vulnerability has a CVSS score of 5.5 (Medium), requiring local access for exploitation and potentially leading to a high impact on availability. While the exploit has been publicly disclosed, there is no evidence of active exploitation, nor are there Metasploit, Nuclei, or ExploitDB modules available. Despite its low EPSS score, the vulnerability has garnered some community discussion, including a recent patch for openSUSE Leap 16.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 27.6CPE matchmatch criteria | cpe:2.3:a:gnu:libopts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.