VDB
KO
MEDIUM 5.9

PYSEC-2026-3544

Quick fix

PYSEC-2026-3544 — capstone: upgrade to the fixed version with the command below.

pip install --upgrade 'capstone>=5.0.8'

Details

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`, allowing a remote attacker to crash any application using the reduced X86 Capstone library by supplying a crafted input containing the 4-byte sequence `0F 0F <modrm> <imm8>`. Versions 6.0.0-Alpha8 and 5.0.8 patch the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / capstone
Introduced in: 0 Fixed in: 5.0.8
Fix pip install --upgrade 'capstone>=5.0.8'

References