GNU Bison improperly handles grammar-defined output path directives. When parsing attacker-supplied grammar files, directives such as %output and %header are accepted without sufficient restriction and can override output locations otherwise supplied by the caller. As a result, generated parser output and header files can be redirected to arbitrary filesystem paths writable by the Bison process. This creates a path control vulnerability that can lead to unauthorized file creation or overwriting of existing files. GNU Bison 3.8.2 was tested and confirmed vulnerable; other versions may also be affected, but a complete vulnerable version range is currently not available. The issue was fixed upstream in commit 8d101c19d4d9aaedf83a448c925513742d4efcf0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A reported vulnerability affecting GNU Bison software.
A path/file overwrite vulnerability in GNU Bison that allows attacker-supplied grammar files to direct generated output to arbitrary writable filesystem locations.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.