Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:13923 - Security Advisory
Issued:
2026-05-06
Updated:
2026-05-06

RHSA-2026:13923 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: capstone security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for capstone is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Capstone is a disassembly framework with the target of becoming the ultimate disasm engine for binary analysis and reversing in the security community.

Security Fix(es):

  • capstone: Capstone: Memory corruption via unchecked vsnprintf return (CVE-2025-68114)
  • capstone: Capstone: Heap buffer overflow via skipdata callback allows denial of service or arbitrary code execution. (CVE-2025-67873)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2423416 - CVE-2025-68114 capstone: Capstone: Memory corruption via unchecked vsnprintf return
  • BZ - 2423419 - CVE-2025-67873 capstone: Capstone: Heap buffer overflow via skipdata callback allows denial of service or arbitrary code execution.

CVEs

  • CVE-2025-67873
  • CVE-2025-68114

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
capstone-4.0.2-5.el9_0.src.rpm SHA-256: 9ecb6dd42594e11039666a447be5cdf087d71ecf4b1ceb22257eb0fa91e8492c
ppc64le
capstone-4.0.2-5.el9_0.ppc64le.rpm SHA-256: f5e9a0dbff9415bc58d8a66a30ac2042511183b6d343f9adc0720be231b0aa3e
capstone-debuginfo-4.0.2-5.el9_0.ppc64le.rpm SHA-256: 9ef1778d4606f5c7c96c968a6ed36f87261b8912c15a9c25d913a188fe1574b6
capstone-debugsource-4.0.2-5.el9_0.ppc64le.rpm SHA-256: a3075cf91791d336e090749938ca2e56275d995f21900f6a212a97a0b1e90a0f
python3-capstone-debuginfo-4.0.2-5.el9_0.ppc64le.rpm SHA-256: c1ec643d80aa4854aae87eedb70b2353760549bf62b0383f3bd40d8d364a608b

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
capstone-4.0.2-5.el9_0.src.rpm SHA-256: 9ecb6dd42594e11039666a447be5cdf087d71ecf4b1ceb22257eb0fa91e8492c
x86_64
capstone-4.0.2-5.el9_0.i686.rpm SHA-256: c9690ccb893235681a4aacbd6b731f526cf3f3d3774fca83b0939b080c42056f
capstone-4.0.2-5.el9_0.x86_64.rpm SHA-256: c6cd96b535b8378a27c255fa0d966443fe65f78c97bbd4b95bccac928c41b0a7
capstone-debuginfo-4.0.2-5.el9_0.i686.rpm SHA-256: 51653d26803b71ee0c5b3a13b304d0dc52944b18573ddc7feca0440204fa1de1
capstone-debuginfo-4.0.2-5.el9_0.x86_64.rpm SHA-256: f8eb03aafa1e1def75dba6016aa6d2c35e05c34320389ac7016b0b09ce1536c2
capstone-debugsource-4.0.2-5.el9_0.i686.rpm SHA-256: 50fa5f3e4fb9546dafaf758dbb9f356562d88eed264c3609a9f85b43c5d67633
capstone-debugsource-4.0.2-5.el9_0.x86_64.rpm SHA-256: 45c8258094bd1983f821f4cecd0d69ece716d055cda945204a8ac7edf31d6bc8
python3-capstone-debuginfo-4.0.2-5.el9_0.i686.rpm SHA-256: 086fc3488f8f8ded88f3e858009e27835840a70823d76959ff7cb79f1f1f6300
python3-capstone-debuginfo-4.0.2-5.el9_0.x86_64.rpm SHA-256: 89e5431471ac26916b91b7aeec9daeacd99b3084089b5ebe2e70d4c1267e5226

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
capstone-4.0.2-5.el9_0.src.rpm SHA-256: 9ecb6dd42594e11039666a447be5cdf087d71ecf4b1ceb22257eb0fa91e8492c
aarch64
capstone-4.0.2-5.el9_0.aarch64.rpm SHA-256: 24d14ecf0e4fbafb8b17c12e36146f03b5c9750297e4a9af74f77bb5c73a8aa2
capstone-debuginfo-4.0.2-5.el9_0.aarch64.rpm SHA-256: 1801af39826a28705619661fb36cee580659d0e04a038a4dd84e690b4641f40b
capstone-debugsource-4.0.2-5.el9_0.aarch64.rpm SHA-256: 5f3f3a691aa208d456b437e54e0ddf2a74430ae04bd776f5a3714bd178cf041c
python3-capstone-debuginfo-4.0.2-5.el9_0.aarch64.rpm SHA-256: c0950b47e8aa98fdd0f197f415cc7b2664eb99a1fd60e496eea613d9b0ee814f

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
capstone-4.0.2-5.el9_0.src.rpm SHA-256: 9ecb6dd42594e11039666a447be5cdf087d71ecf4b1ceb22257eb0fa91e8492c
s390x
capstone-4.0.2-5.el9_0.s390x.rpm SHA-256: 8c00d9bf2b4734c48ea82998b6a84ad8d8cbb653149debbda01d2188afdaf8a7
capstone-debuginfo-4.0.2-5.el9_0.s390x.rpm SHA-256: 8868b85f5c0f99886174ee2a427866e0353a48f81bde817a2fc178b246f6fdef
capstone-debugsource-4.0.2-5.el9_0.s390x.rpm SHA-256: 6ce37185bce8945c13553bcc2540b56b95df7e53be2f565cd915c964e610bf66
python3-capstone-debuginfo-4.0.2-5.el9_0.s390x.rpm SHA-256: 42d43252d3fdaefd4318ce11515df37176a984743b30536aae9d3547e77d07bf

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility