CVE-2025-69720

Published: March 21, 2026Last modified: March 24, 2026

Description

ncurses v6.5 and v6.4 are vulnerable to Buffer Overflow in progs/infocmp.c, function analyze_string().

Severity score breakdown

ParameterValue
Base score7.8
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSncursesFixed (6.3_p20221119-r3)
25 LTSncursesFixed (6.5_p20250503-r1)
StreamncursesFixed (6.6_p20251231-r0)
Hardened Containers23 LTSncursesFixed (6.3_p20221119-r3)
25 LTSncursesFixed (6.5_p20250503-r1)
StreamncursesFixed (6.6_p20251231-r0)

References

ON THIS PAGE