Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66554.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-66554
Upstream
Published
2025-08-21T14:15:44Z
Modified
2026-04-21T04:37:54.758877Z
Summary
CVE-2025-9301 affecting package cmake for versions less than 3.21.4-19
Details

A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::ReplayItems of the file cmForEachCommand.cxx. This manipulation causes reachable assertion. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. Patch name: 37e27f71bc356d880c908040cd0cb68fa2c371b8. It is suggested to install a patch to address this issue.

References

Affected packages

Azure Linux:2 / cmake

Package

Name
cmake
Purl
pkg:rpm/azure-linux/cmake

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.21.4-19

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66554.json"