UBUNTU-CVE-2025-67125

Source
https://ubuntu.com/security/CVE-2025-67125
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67125.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-67125
Upstream
  • CVE-2025-67125
Published
2026-01-26T00:00:00Z
Modified
2026-01-27T13:00:55.033031Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A signed integer overflow in docopt.cpp v0.6.2 (LeafPattern::match in docoptprivate.h) when merging occurrence counters (e.g., default LONGMAX + first user "-v/--verbose") can cause counter wrap (negative/unbounded semantics) and lead to logic/policy bypass in applications that rely on occurrence-based limits, rate-gating, or safety toggles. In hardened builds (e.g., UBSan or -ftrapv), the overflow may also result in process abort (DoS).

References

Affected packages

Ubuntu:18.04:LTS / docopt.cpp

Package

Name
docopt.cpp
Purl
pkg:deb/ubuntu/docopt.cpp@0.6.2-2?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.6.2-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libdocopt-dev",
            "binary_version": "0.6.2-2"
        },
        {
            "binary_name": "libdocopt0",
            "binary_version": "0.6.2-2"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67125.json"

Ubuntu:20.04:LTS / docopt.cpp

Package

Name
docopt.cpp
Purl
pkg:deb/ubuntu/docopt.cpp@0.6.2-2build1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.6.2-2
0.6.2-2build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libdocopt-dev",
            "binary_version": "0.6.2-2build1"
        },
        {
            "binary_name": "libdocopt0",
            "binary_version": "0.6.2-2build1"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67125.json"

Ubuntu:22.04:LTS / docopt.cpp

Package

Name
docopt.cpp
Purl
pkg:deb/ubuntu/docopt.cpp@0.6.2-2.3?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.6.2-2.1
0.6.2-2.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libdocopt-dev",
            "binary_version": "0.6.2-2.3"
        },
        {
            "binary_name": "libdocopt0",
            "binary_version": "0.6.2-2.3"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67125.json"

Ubuntu:24.04:LTS / docopt.cpp

Package

Name
docopt.cpp
Purl
pkg:deb/ubuntu/docopt.cpp@0.6.3-4build1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.6.2-2.4
0.6.3-4
0.6.3-4build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libdocopt-dev",
            "binary_version": "0.6.3-4build1"
        },
        {
            "binary_name": "libdocopt0",
            "binary_version": "0.6.3-4build1"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67125.json"

Ubuntu:25.10 / docopt.cpp

Package

Name
docopt.cpp
Purl
pkg:deb/ubuntu/docopt.cpp@0.6.3-5?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.6.3-5

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libdocopt-dev",
            "binary_version": "0.6.3-5"
        },
        {
            "binary_name": "libdocopt0",
            "binary_version": "0.6.3-5"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67125.json"