CVE-2024-58350

Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and XmlArchitectureCapability singletons. Attackers can trigger an infinite loop or denial of service during shutdown by exploiting the unsafe destruction order that causes iteration over deallocated memory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-10 14:16

Updated : 2026-07-14 23:17


NVD link : CVE-2024-58350

Mitre link : CVE-2024-58350

CVE.ORG link : CVE-2024-58350


JSON object : View

Products Affected

nsa

  • ghidra
CWE
CWE-758

Reliance on Undefined, Unspecified, or Implementation-Defined Behavior