Home

Description

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. CodeChecker versions up to 6.26.1 contain a buffer overflow vulnerability in the internal ldlogger library, which is executed by the CodeChecker log command. This issue affects CodeChecker: through 6.26.1.

PUBLISHED Reserved 2025-04-16 | Published 2025-10-28 | Updated 2025-10-28 | Assigner ERIC




MEDIUM: 5.9CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Problem types

CWE-121 Stack based buffer overflow

Product status

Default status
unaffected

Any version
affected

References

github.com/...hecker/security/advisories/GHSA-5xf2-f6ch-6p8r vendor-advisory

cve.org (CVE-2025-40843)

nvd.nist.gov (CVE-2025-40843)

Download JSON