GitHub Security Advisory (GHSA-4g43-2f29-xvp4)Vendor advisory
https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-4g43-2f29-xvp4 CVE-2024-58350
LOW
Ghidra < 11.2 - Use After Free in Sleigh Backend via Static Initialization Order
Record summary
CVE-2024-58350 has a selected CVSS score of 2.1 (low).
Description
Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and XmlArchitectureCapability singletons. Attackers can trigger an infinite loop or denial of service during shutdown by exploiting the unsafe destruction order that causes iteration over deallocated memory.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 10, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 11.2 | affected |
| 11.2 | unaffected |
References
2vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/ghidra-use-after-free-in-sleigh-backend-via-static-initialization-order