UPX is a widely deployed executable packer and compression utility that reduces binary size across multiple platforms, giving it substantial presence in the software supply chain despite a narrow product scope. The vulnerability profile centers on its core compression and decompression engine, where recurring weaknesses cluster around memory-safety issues including buffer overflows, out-of-bounds reads and writes, and arithmetic faults such as division-by-zero conditions that arise during format parsing and unpacking operations. These classes reflect the low-level binary manipulation inherent to a packer's design and the parsing complexity involved in handling diverse executable formats. Defenders should treat UPX-packed binaries as a potential vector for exploitation when the packer itself is vulnerable, since patching typically requires repacking or replacing affected binaries rather than standard patching workflows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Upx over time
Signals from CVEs in this vendor scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3209CRITICAL A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffe | Apr 2, 2024 | 9.8 | 27 | NO | NO |
CVE-2020-27801HIGH A heap-based buffer over-read was discovered in the get_le64 function in bele.h in UPX 4.0.0 via a crafted Mach-O file. | Aug 25, 2022 | 7.8 | 25 | NO | NO |
CVE-2020-27800HIGH A heap-based buffer over-read was discovered in the get_le32 function in bele.h in UPX 4.0.0 via a crafted Mach-O file. | Aug 25, 2022 | 7.8 | 25 | NO | NO |
CVE-2020-27799HIGH A heap-based buffer over-read was discovered in the acc_ua_get_be32 function in miniacc.h in UPX 4.0.0 via a crafted Mach-O file. | Aug 25, 2022 | 7.8 | 25 | NO | NO |
CVE-2020-27796HIGH A heap-based buffer over-read was discovered in the invert_pt_dynamic function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file. | Aug 25, 2022 | 7.8 | 25 | NO | NO |
CVE-2019-14296HIGH canUnpack in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (SEGV or buffer overflow, and application crash) or possibly have unspecified other impac | Jul 27, 2019 | 7.8 | 25 | NO | NO |
CVE-2018-11243HIGH PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of a malware scanner to operate on the enti | May 18, 2018 | 7.8 | 25 | NO | NO |
CVE-2017-16869HIGH p_mach.cpp in UPX 3.94 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted Ma | Nov 17, 2017 | 7.8 | 25 | NO | NO |
CVE-2021-43317HIGH A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackL | Mar 24, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-43316HIGH A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le64(). | Mar 24, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (35 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Upx.
Media articles that mention a CVE ID that affects a product developed by Upx — matched by CVE ID, not by vendor name.