CVE-2025-8746 | GNU libopts up to 27.6 __strstr_sse2 memory corruption (Issue 957 / EUVD-2025-24045)
A vulnerability classified as problematic has been found in GNU libopts up to 27.6. Affected is the function __strstr_sse2. The manipulation leads to memory corruption. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is documented as CVE-2025-8746. The attack needs to be performed locally. Additionally, an exploit exists.
This issue was initially reported to the tcpreplay project, but the code maintainer explains, that this "bug appears to be in libopts which is an external library."