A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::ReplayItems of the file cmForEachCommand.cxx. This manipulation causes reachable assertion. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. Patch name: 37e27f71bc356d880c908040cd0cb68fa2c371b8. It is suggested to install a patch to address this issue.
CVSS Details
- CVSS 4.0 Base Score: 1.9 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Huawei Euleros 2_0_sp11 | — | Upgrade cmake-filesystemUpgrade cmake-dataUpgrade cmake-helpUpgrade cmakeUpgrade cmake-rpm-macros | Dec 12, 2025 | Nov 11, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade cmake-filesystemUpgrade cmake-rpm-macrosUpgrade cmake-dataUpgrade cmakeUpgrade cmake-help | Nov 12, 2025 | Nov 11, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade cmakeUpgrade cmake-helpUpgrade cmake-rpm-macrosUpgrade cmake-dataUpgrade cmake-filesystem | Dec 12, 2025 | Nov 11, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Aug 21, 2025 |
| Suse | — | Upgrade cmakeUpgrade cmake-manUpgrade cmake3-fullUpgrade cmake-fullUpgrade cmake3Upgrade cmake-gui | Dec 5, 2025 | Aug 25, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub