CVE-2024-58350CWE-758

Ghidra < 11.2 - Use After Free in Sleigh Backend via Static Initialization Order

Low · published June 10, 2026

CVSS v4.0
2.1
EPSS
0%
Percentile
1.4
In the wild
Unconfirmed
What it is

Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and XmlArchitectureCapability singletons. Attackers can trigger an infinite loop or denial of service during shutdown by exploiting the unsafe destruction order that causes iteration over deallocated memory.

The record
Technical detail
CVSS v4.0
2.1 · LOW
Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
EPSS
0.00110 · 1.4th percentile
Weakness
CWE-758 · Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
Published
2026-06-10T12:36Z
EPSS history
Timeline
  • 10 JUN 12:36Z
    Ghidra < 11.2 - Use After Free in Sleigh Backend via Static Initialization Order
    cvelistv5