Heap-based buffer overflow in the xioscan_readline function in xio-readline.c in socat 1.4.0.0 through 1.7.2.0 and 2.0.0-b1 through 2.0.0-b4 allows local users to execute arbitrary code via the READLINE address.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade socat | Jul 30, 2024 | Jun 21, 2012 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | May 29, 2015 |
| Freebsd | — | Upgrade socat | Dec 10, 2025 | May 14, 2012 |
| Gentoo Linux | — | Upgrade net-misc/socat. | Oct 30, 2017 | Jun 21, 2012 |
| Suse | — | Upgrade socat-debugsourceUpgrade socat-debuginfoUpgrade socat | Dec 12, 2013 | Jun 21, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub