CVE 5.3 MEDIUM

PCSX2 has an Out-of-bounds Read due to unchecked offset and size passed to memcpy_CVE-2025-67749

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

Description

PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. In versions 2.5.377 and below, an unchecked offset and size used in a memcpy operation inside PCSX2's CDVD SCMD 0x91 and SCMD 0x8F handlers allow a specially crafted disc image or ELF to cause an out-of-bounds read from emulator memory. Because the offset and size is controlled through MG header fields, a specially crafted ELF can read data beyond the bounds of mg_buffer and have it reflected back into emulated memory. This issue is fixed in version 2.5.378.

Basic Information

ID CVE-2025-67749
Source GitHub_M
Published Dec 12, 2025 at 22:24

Affected Product

Vendor PCSX2
Product pcsx2
Version < 2.5.378
Affected Versions PCSX2 pcsx2 < 2.5.378

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.