PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. A stack-based buffer overflow exists in the Kprintf_HLE function of PCSX2 versions up to 2.3.414. Opening a disc image that logs a specially crafted message may allow a remote attacker to execute arbitrary code if the user enabled IOP Console Logging. This vulnerability is fixed in 2.3.414.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49589.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-121"
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49589.json"
"2026-04-12T17:14:04Z"
[
{
"target": {
"file": "pcsx2/IopBios.cpp",
"function": "Kprintf_HLE"
},
"id": "CVE-2025-49589-4039b428",
"source": "https://github.com/pcsx2/pcsx2/commit/8eb46b5a4c0380d59cb540f8b5f59daf8e609bd7",
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2201.0,
"function_hash": "169794206469229345927153284177244026874"
},
"signature_version": "v1"
},
{
"target": {
"file": "pcsx2/IopBios.cpp"
},
"id": "CVE-2025-49589-a7e32942",
"source": "https://github.com/pcsx2/pcsx2/commit/8eb46b5a4c0380d59cb540f8b5f59daf8e609bd7",
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"147726117125906117697463769696749802512",
"69728203197863330295289001298863540711",
"225918791055159150785385877403525815795",
"314339809360225367837422909860120062817",
"160036719101153102789216188380510428846",
"200944485539230173925769253988832250513",
"224822061229156604471256170092138793510",
"166946998660937214346946038287384318491",
"25827218575565183146563655856745415048",
"191676479660312178241703274875467575913",
"34268443833055182237836883989514218285",
"187496369033525408398787610068620433765",
"143974157863372655943659783612160397449"
]
},
"signature_version": "v1"
}
]