CVE-2025-40843: CodeChecker has a buffer overflow in the log command
(updated )
CodeChecker versions up to 6.26.1 contain a buffer overflow vulnerability in the internal ldlogger library, which is executed by the CodeChecker log command.
References
- github.com/Ericsson/codechecker/commit/4122eb1b43d00c880e4f0747d2ca0a674feb7a50
- github.com/Ericsson/codechecker/security/advisories/GHSA-5xf2-f6ch-6p8r
- github.com/advisories/GHSA-5xf2-f6ch-6p8r
- github.com/pypa/advisory-database/tree/main/vulns/codechecker/PYSEC-2025-100.yaml
- nvd.nist.gov/vuln/detail/CVE-2025-40843
Code Behaviors & Features
Detect and mitigate CVE-2025-40843 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →