Vulnerability Description
Out-of-bounds write in cdfs_open_cue_track in libretro libretro-common latest on all platforms allows remote attackers to execute arbitrary code via a crafted .cue file with a file path exceeding PATH_MAX_LENGTH that is copied using memcpy into a fixed-size buffer.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libretro | Libretro-Common | - |
Related Weaknesses (CWE)
References
- https://github.com/libretro/libretro-common/blob/master/formats/cdfs/cdfs.c#L471Product
- https://github.com/libretro/libretro-common/issues/222Issue TrackingThird Party Advisory
FAQ
What is CVE-2025-9809?
CVE-2025-9809 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Out-of-bounds write in cdfs_open_cue_track in libretro libretro-common latest on all platforms allows remote attackers to execute arbitrary code via a crafted .cue file with a file path exceeding PATH...
How severe is CVE-2025-9809?
CVE-2025-9809 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-9809?
Check the references section above for vendor advisories and patch information. Affected products include: Libretro Libretro-Common.