CVE-2025-9136

A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This affects the function filestream_vscanf of the file libretro-common/streams/file_stream.c. This manipulation causes out-of-bounds read. The attack needs to be launched locally. Upgrading to version 1.21.0 mitigates this issue. It is recommended to upgrade the affected component.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libretro:retroarch:1.18.0:*:*:*:*:*:*:*
cpe:2.3:a:libretro:retroarch:1.19.0:*:*:*:*:*:*:*
cpe:2.3:a:libretro:retroarch:1.20.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-19 12:15

Updated : 2025-09-12 14:55


NVD link : CVE-2025-9136

Mitre link : CVE-2025-9136

CVE.ORG link : CVE-2025-9136


JSON object : View

Products Affected

libretro

  • retroarch
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-125

Out-of-bounds Read