🔐 CVE Alert

CVE-2026-58106

UNKNOWN 0.0

Incomplete fix for CVE-2025-40843: safe_strcpy is called with PATH_MAX into fullPath+2, writing 2 bytes past the buffer on every CodeChecker log invocation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r  was fixed by replacing unchecked strcpy() with a bounded safe_strcpy() helper. At ldlogger-tool-gcc.c:129 the destination passed to that helper is fullPath + 2, but the size passed down is the full PATH_MAX. safe_strcpy() is strncpy(), which NUL-pads the destination out to the whole n, so this site writes 4096 bytes into the 4094 that remain — a 2-byte stack overflow on every invocation, independent of the input path's length. This issue affects CodeChecker: through 6.28.2.

CWE CWE-787
Vendor ericsson
Product codechecker
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for ericsson codechecker

Be the first to know when new unknown vulnerabilities affecting ericsson codechecker are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Ericsson / CodeChecker
0 ≤ 6.28.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/Ericsson/codechecker/security/advisories/GHSA-9gcg-v8fg-39q8

Credits

Fatullayev Asadbek