CVE-2025-9301 is a low-severity vulnerability affecting cmake version 4.1.20250725-gb5cce23, specifically within the cmForEachFunctionBlocker::ReplayItems function in cmForEachCommand.cxx. This flaw can lead to a reachable assertion, potentially causing a denial of service. The attack requires local access and has a low impact on availability, with no impact on confidentiality or integrity. While the exploit has been publicly disclosed, there is no evidence of active exploitation, and it lacks exploit code in common frameworks or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Cmake | 4.1.20250725-gb5cce23CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.