CVE-2025-5222
Icu: stack buffer overflow in the srbroot::addtag function
Record summary
CVE-2025-5222 has a selected CVSS score of 7.0 (high); EIP currently links 1 repository PoC.
Description
A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 28, 2025 · Source: CVE List
Affected products and versions
12| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | 0:74.2-5.el10_0 to < * | unaffected |
Default status: unknown | CVE List | Version data not supplied | |
Default status: unknown | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | 0:67.1-10.el9_6 to < * | unaffected |
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsBrowse Red Hat / Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsicuDefault status: affected | CVE List | 0:67.1-10.el9_0 to < * | unaffected |
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsBrowse Red Hat / Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsicuDefault status: affected | CVE List | 0:67.1-10.el9_2 to < * | unaffected |
Red Hat Enterprise Linux 9.4 Extended Update SupportBrowse Red Hat / Red Hat Enterprise Linux 9.4 Extended Update SupporticuDefault status: affected | CVE List | 0:67.1-10.el9_4 to < * | unaffected |
Default status: affected | CVE List | Version data not supplied | |
SIDIS Secured SmartPlugBrowse Siemens / SIDIS Secured SmartPlugDefault status: unknown | CVE List | Before V7.26.0310 | affected |
icuDefault status: unaffected | CVE List | Before 78.1 | affected |