Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:4898 - Security Advisory
Issued:
2026-03-18
Updated:
2026-03-18

RHSA-2026:4898 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: capstone security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for capstone is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Capstone is a disassembly framework with the target of becoming the ultimate disasm engine for binary analysis and reversing in the security community.

Security Fix(es):

  • capstone: Capstone: Memory corruption via unchecked vsnprintf return (CVE-2025-68114)
  • capstone: Capstone: Heap buffer overflow via skipdata callback allows denial of service or arbitrary code execution. (CVE-2025-67873)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 9 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x

Fixes

  • BZ - 2423416 - CVE-2025-68114 capstone: Capstone: Memory corruption via unchecked vsnprintf return
  • BZ - 2423419 - CVE-2025-67873 capstone: Capstone: Heap buffer overflow via skipdata callback allows denial of service or arbitrary code execution.

CVEs

  • CVE-2025-67873
  • CVE-2025-68114

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
capstone-4.0.2-11.el9_7.src.rpm SHA-256: 9053f3d5554869644bf37e3b99478a2e1ba7e46eec5e63e0c7daa3e190a9bc0f
x86_64
capstone-4.0.2-11.el9_7.i686.rpm SHA-256: da7de72884adc1f9f7faf3c38f7999ab9af12b7022573bd3d2109438f03bb7ee
capstone-4.0.2-11.el9_7.x86_64.rpm SHA-256: 3d09948696a715d830047ebaba290ac50de3dc90346c3c61da68e909577ac5bb
capstone-debuginfo-4.0.2-11.el9_7.i686.rpm SHA-256: 3fa7d36a9666da18559797ea60a7d305cc2efc5fa23227634eef39fe428424d5
capstone-debuginfo-4.0.2-11.el9_7.x86_64.rpm SHA-256: b8989f945aff1c6f1a3d367b737697e6c04052791da4e318e3fc47f963b06d4c
capstone-debugsource-4.0.2-11.el9_7.i686.rpm SHA-256: 7644b7945f35635517f3f76157f1a89bbde3d96ab9b09b879548fb54415208e8
capstone-debugsource-4.0.2-11.el9_7.x86_64.rpm SHA-256: 97d5db8a7e8365715c8f7f45a9eee15b02d9bacd79a046449a316734ac8c7c8b
python3-capstone-debuginfo-4.0.2-11.el9_7.i686.rpm SHA-256: 4b490500c5afe2dda70e2561927cd5941d4c9589e757be743c160cebef01a5eb
python3-capstone-debuginfo-4.0.2-11.el9_7.x86_64.rpm SHA-256: e72e6cf891f2cebeadf7011aa19a562197b60b56626b54f83670ac0e6b7ca565

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
capstone-4.0.2-11.el9_7.src.rpm SHA-256: 9053f3d5554869644bf37e3b99478a2e1ba7e46eec5e63e0c7daa3e190a9bc0f
s390x
capstone-4.0.2-11.el9_7.s390x.rpm SHA-256: 4cfdcae243d4c3be940805665593d95796d3cf2e3fc4745c5c390bc9aaf57f45
capstone-debuginfo-4.0.2-11.el9_7.s390x.rpm SHA-256: a7eb6a1eb0bd47548b760b0bcbb023f92d0e88751949708fbeacc8d4b661cacb
capstone-debugsource-4.0.2-11.el9_7.s390x.rpm SHA-256: f893fc11bb1f47d123903729d88e83734a86456e44237ba35666d33f74128f79
python3-capstone-debuginfo-4.0.2-11.el9_7.s390x.rpm SHA-256: 033766d268aefeb190449414ca312a08ed4b09d25d925869e65fcfdc6512cb5c

Red Hat Enterprise Linux for Power, little endian 9

SRPM
capstone-4.0.2-11.el9_7.src.rpm SHA-256: 9053f3d5554869644bf37e3b99478a2e1ba7e46eec5e63e0c7daa3e190a9bc0f
ppc64le
capstone-4.0.2-11.el9_7.ppc64le.rpm SHA-256: 8a8b73bb79bac5509669ca6afa1764480e2e007a1398ee52aef8587a7ba7b292
capstone-debuginfo-4.0.2-11.el9_7.ppc64le.rpm SHA-256: 2384001c4813cb579fdab512d623ce2c597bd5b5a0f448528a052cc25c99d421
capstone-debugsource-4.0.2-11.el9_7.ppc64le.rpm SHA-256: 33b05235b63f9d5c4dd8439f406763a01af1a6da17fb5bafe28a2c3942240b83
python3-capstone-debuginfo-4.0.2-11.el9_7.ppc64le.rpm SHA-256: ef7f7b06099ff8ae3c65adda6c58825ed98db97fe3203928fb73ed1aad92fad9

Red Hat Enterprise Linux for ARM 64 9

SRPM
capstone-4.0.2-11.el9_7.src.rpm SHA-256: 9053f3d5554869644bf37e3b99478a2e1ba7e46eec5e63e0c7daa3e190a9bc0f
aarch64
capstone-4.0.2-11.el9_7.aarch64.rpm SHA-256: 6e6ecc98106963c9e1842bc35d1e80455748976e136ae4a198db8a9c9009f8a5
capstone-debuginfo-4.0.2-11.el9_7.aarch64.rpm SHA-256: cabaffa2fe48b0742b05e7621d4d889be02c2fd0153ea8690120531ab21d739d
capstone-debugsource-4.0.2-11.el9_7.aarch64.rpm SHA-256: 7f87e99ddd09e7f4ed8839eae9247edab5fbb577057afb6017414493c6a2ddd7
python3-capstone-debuginfo-4.0.2-11.el9_7.aarch64.rpm SHA-256: 86b7b8ad7ca587228ee55c5f8bbeaa3aaaa087ef952503687b2f20c3c1bea127

Red Hat CodeReady Linux Builder for x86_64 9

SRPM
x86_64
capstone-debuginfo-4.0.2-11.el9_7.i686.rpm SHA-256: 3fa7d36a9666da18559797ea60a7d305cc2efc5fa23227634eef39fe428424d5
capstone-debuginfo-4.0.2-11.el9_7.x86_64.rpm SHA-256: b8989f945aff1c6f1a3d367b737697e6c04052791da4e318e3fc47f963b06d4c
capstone-debugsource-4.0.2-11.el9_7.i686.rpm SHA-256: 7644b7945f35635517f3f76157f1a89bbde3d96ab9b09b879548fb54415208e8
capstone-debugsource-4.0.2-11.el9_7.x86_64.rpm SHA-256: 97d5db8a7e8365715c8f7f45a9eee15b02d9bacd79a046449a316734ac8c7c8b
capstone-devel-4.0.2-11.el9_7.i686.rpm SHA-256: 5e8d72f851807810a4be026d0e7d0c5e0f4f6e88ed3adbf45e727781fadf1f71
capstone-devel-4.0.2-11.el9_7.x86_64.rpm SHA-256: cbc9f3cd5784e5b33eac7359cfeaca8f723fbc7a8af5dfe599f0b5cb86f90237
capstone-java-4.0.2-11.el9_7.noarch.rpm SHA-256: 876e615dd27bd258cbc5946c51a33b32c91098b061ecea1e818fc432bed2997a
python3-capstone-4.0.2-11.el9_7.x86_64.rpm SHA-256: 35ded18a6f0a373969b42a1ba7e6fd53fd3dc7333371be77eb56d10ecac83804
python3-capstone-debuginfo-4.0.2-11.el9_7.i686.rpm SHA-256: 4b490500c5afe2dda70e2561927cd5941d4c9589e757be743c160cebef01a5eb
python3-capstone-debuginfo-4.0.2-11.el9_7.x86_64.rpm SHA-256: e72e6cf891f2cebeadf7011aa19a562197b60b56626b54f83670ac0e6b7ca565

Red Hat CodeReady Linux Builder for Power, little endian 9

SRPM
ppc64le
capstone-debuginfo-4.0.2-11.el9_7.ppc64le.rpm SHA-256: 2384001c4813cb579fdab512d623ce2c597bd5b5a0f448528a052cc25c99d421
capstone-debugsource-4.0.2-11.el9_7.ppc64le.rpm SHA-256: 33b05235b63f9d5c4dd8439f406763a01af1a6da17fb5bafe28a2c3942240b83
capstone-devel-4.0.2-11.el9_7.ppc64le.rpm SHA-256: 149e6a9919b8953b06ec2d46588a42422fb0aa7ffe358ff153f0f7721b61bd52
capstone-java-4.0.2-11.el9_7.noarch.rpm SHA-256: 876e615dd27bd258cbc5946c51a33b32c91098b061ecea1e818fc432bed2997a
python3-capstone-4.0.2-11.el9_7.ppc64le.rpm SHA-256: 4e5ae0ba4966aa33b19ba1603a2369858335805994e61ce80f22704d6ea14fbc
python3-capstone-debuginfo-4.0.2-11.el9_7.ppc64le.rpm SHA-256: ef7f7b06099ff8ae3c65adda6c58825ed98db97fe3203928fb73ed1aad92fad9

Red Hat CodeReady Linux Builder for ARM 64 9

SRPM
aarch64
capstone-debuginfo-4.0.2-11.el9_7.aarch64.rpm SHA-256: cabaffa2fe48b0742b05e7621d4d889be02c2fd0153ea8690120531ab21d739d
capstone-debugsource-4.0.2-11.el9_7.aarch64.rpm SHA-256: 7f87e99ddd09e7f4ed8839eae9247edab5fbb577057afb6017414493c6a2ddd7
capstone-devel-4.0.2-11.el9_7.aarch64.rpm SHA-256: a05e7f3646159871f9985745ab71c291fb28d120b79d60023b0ef3bf2c71ac6c
capstone-java-4.0.2-11.el9_7.noarch.rpm SHA-256: 876e615dd27bd258cbc5946c51a33b32c91098b061ecea1e818fc432bed2997a
python3-capstone-4.0.2-11.el9_7.aarch64.rpm SHA-256: b3043dbc268dfc574cb5d2d4c420f1f73a03c56a356cd118dd8cfca74a847c0c
python3-capstone-debuginfo-4.0.2-11.el9_7.aarch64.rpm SHA-256: 86b7b8ad7ca587228ee55c5f8bbeaa3aaaa087ef952503687b2f20c3c1bea127

Red Hat CodeReady Linux Builder for IBM z Systems 9

SRPM
s390x
capstone-debuginfo-4.0.2-11.el9_7.s390x.rpm SHA-256: a7eb6a1eb0bd47548b760b0bcbb023f92d0e88751949708fbeacc8d4b661cacb
capstone-debugsource-4.0.2-11.el9_7.s390x.rpm SHA-256: f893fc11bb1f47d123903729d88e83734a86456e44237ba35666d33f74128f79
capstone-devel-4.0.2-11.el9_7.s390x.rpm SHA-256: 04056960c94f0e434f4a7bddbe5dc813206eb93b9f30ad2312419181e22250d3
capstone-java-4.0.2-11.el9_7.noarch.rpm SHA-256: 876e615dd27bd258cbc5946c51a33b32c91098b061ecea1e818fc432bed2997a
python3-capstone-4.0.2-11.el9_7.s390x.rpm SHA-256: fca973eb3b9703c7e753b0575ccd0b8de3c4ac23cd722aebc2dc94ab8661f4bd
python3-capstone-debuginfo-4.0.2-11.el9_7.s390x.rpm SHA-256: 033766d268aefeb190449414ca312a08ed4b09d25d925869e65fcfdc6512cb5c

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility