Record summary

CVE-2025-5222 has a selected CVSS score of 7.0 (high); EIP currently links 1 repository PoC.

Description

A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 28, 2025 · Source: CVE List

Affected products and versions

12
ProductSourceVersion rangeStatus

Red Hat Enterprise Linux 10

Browse Red Hat / Red Hat Enterprise Linux 10icu

Default status: affected

CVE List0:74.2-5.el10_0 to < *unaffected

Red Hat Enterprise Linux 6

Browse Red Hat / Red Hat Enterprise Linux 6icu

Default status: unknown

CVE ListVersion data not supplied

Red Hat Enterprise Linux 7

Browse Red Hat / Red Hat Enterprise Linux 7icu

Default status: unknown

CVE ListVersion data not supplied

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8icu

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8mingw-icu

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 9

Browse Red Hat / Red Hat Enterprise Linux 9icu

Default status: affected

CVE List0:67.1-10.el9_6 to < *unaffected

Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Browse Red Hat / Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionsicu

Default status: affected

CVE List0:67.1-10.el9_0 to < *unaffected

Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Browse Red Hat / Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionsicu

Default status: affected

CVE List0:67.1-10.el9_2 to < *unaffected

Red Hat Enterprise Linux 9.4 Extended Update Support

Browse Red Hat / Red Hat Enterprise Linux 9.4 Extended Update Supporticu

Default status: affected

CVE List0:67.1-10.el9_4 to < *unaffected

Red Hat OpenShift Container Platform 4

Browse Red Hat / Red Hat OpenShift Container Platform 4rhcos

Default status: affected

CVE ListVersion data not supplied

Default status: unknown

CVE ListBefore V7.26.0310affected

icu

Default status: unaffected

CVE ListBefore 78.1affected

Proofs of concept

1

Repository PoCs

GitHubberkley4/icu-74-debianRepository PoCby berkley4Stars: 2Not analyzed28 files

147.2 KiB

GitHub

PoC details

References

11