A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::ReplayItems of the file cmForEachCommand.cxx. This manipulation causes reachable assertion. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. Patch name: 37e27f71bc356d880c908040cd0cb68fa2c371b8. It is suggested to install a patch to address this issue.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-9301.json"
[
{
"signature_type": "Line",
"source": "https://gitlab.kitware.com/cmake/cmake@37e27f71bc356d880c908040cd0cb68fa2c371b8",
"id": "CVE-2025-9301-09a05382",
"deprecated": false,
"target": {
"file": "Source/cmForEachCommand.cxx"
},
"signature_version": "v1",
"digest": {
"line_hashes": [
"228043602418574992660422980917345339206",
"45640607635578571517308188507225526581",
"87054998341120757898501218577121764349",
"72846618754852695696322263449499194572"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"source": "https://gitlab.kitware.com/cmake/cmake@37e27f71bc356d880c908040cd0cb68fa2c371b8",
"id": "CVE-2025-9301-ef7bf956",
"deprecated": false,
"target": {
"function": "cmForEachFunctionBlocker::Replay",
"file": "Source/cmForEachCommand.cxx"
},
"signature_version": "v1",
"digest": {
"length": 185.0,
"function_hash": "302829191689443455907304212024363053501"
}
}
]