CVE-2025-69720 is a stack-based buffer overflow in the analyze_string function of the infocmp command-line utility in ncurses, located in progs/infocmp.c. It affects ncurses versions before 6.5-20251213. Processing attacker-controlled input can overflow a stack buffer, causing memory corruption and potentially terminating the utility or enabling code execution depending on runtime protections and exploitability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal proof-of-concept for CVE-2025-69720, a stack-based buffer overflow in ncurses infocmp when the -i option analyzes crafted terminfo strings. The repository contains only two files: a README documenting the vulnerability, affected versions, reproduction steps, and ASan crash evidence; and evil_sgr.ti, the actual malicious terminfo source used as the exploit input. There is no standalone executable exploit script or framework integration. The exploit capability is local and data-driven: the attacker supplies a specially crafted terminfo entry whose sgr capability contains an extremely long CSI parameter list. After compiling this file with tic into a terminfo database and pointing TERMINFO to that database, running infocmp -i evil_sgr causes infocmp's analyze_string() routine to copy an overlong substring into a fixed-size 4096-byte stack buffer (buf2) without validating strlen(cp). The demonstrated result is a reproducible stack-buffer overflow and process abort under ASan, consistent with local denial of service. The README explicitly notes that the vulnerable path is specific to the -i analysis option and does not affect ordinary infocmp usage without -i. Repository structure is straightforward: README.md serves as the advisory and usage guide, while evil_sgr.ti is the core PoC artifact and effective entry point. No network communication, command-and-control behavior, persistence, or post-exploitation payloads are present. The only notable observables are local file paths, TERMINFO usage, and reference URLs for source tarballs, vendor news, and the official patch.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity, locally exploitable stack-based buffer overflow in the analyze_string function of the ncurses infocmp command-line tool. It affects ncurses versions prior to 6.5-20251213 and can affect confidentiality, integrity, and availability when user interaction occurs.
A vulnerability addressed by Huawei EulerOS SA-2026-3529 in affected ncurses packages on EulerOS 2.11.0. The CVSS v3 vector indicates a local attack with low complexity and no privileges required, but requiring user interaction, with high confidentiality, integrity, and availability impact.
A locally accessible vulnerability affecting the listed EulerOS ncurses packages. The supplied CVSS v3 vector indicates that exploitation requires user interaction but no privileges, and may result in high confidentiality, integrity, and availability impact.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.