CVE-2025-9301
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
21/08/2025
Last modified:
22/08/2025
Description
A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::ReplayItems of the file cmForEachCommand.cxx. This manipulation causes reachable assertion. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. Patch name: 37e27f71bc356d880c908040cd0cb68fa2c371b8. It is suggested to install a patch to address this issue.
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM
Base Score 3.x
3.30
Severity 3.x
LOW
Base Score 2.0
1.70
Severity 2.0
LOW
References to Advisories, Solutions, and Tools
- https://drive.google.com/file/d/1TerUqQB8_lzJTwIBCBmE94zn7n-gOz4f/view?usp=sharing
- https://gitlab.kitware.com/cmake/cmake/-/commit/37e27f71bc356d880c908040cd0cb68fa2c371b8
- https://gitlab.kitware.com/cmake/cmake/-/issues/27135
- https://gitlab.kitware.com/cmake/cmake/-/issues/27135#note_1691629
- https://vuldb.com/?ctiid_320906=
- https://vuldb.com/?id_320906=
- https://vuldb.com/?submit_632369=



