CVE-2025-49589
Publication date 12 June 2025
Last updated 18 June 2025
Ubuntu priority
PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. A stack-based buffer overflow exists in the Kprintf_HLE function of PCSX2 versions up to 2.3.414. Opening a disc image that logs a specially crafted message may allow a remote attacker to execute arbitrary code if the user enabled IOP Console Logging. This vulnerability is fixed in 2.3.414.
Status
Package | Ubuntu Release | Status |
---|---|---|
pcsx2 | 25.04 plucky |
Needs evaluation
|
24.10 oracular |
Needs evaluation
|
|
24.04 LTS noble |
Needs evaluation
|
|
22.04 LTS jammy |
Needs evaluation
|
|
20.04 LTS focal |
Needs evaluation
|
|
18.04 LTS bionic |
Needs evaluation
|
|
16.04 LTS xenial |
Needs evaluation
|
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2025-49589
- https://github.com/PCSX2/pcsx2/security/advisories/GHSA-f494-4xf7-xj35
- https://github.com/PCSX2/pcsx2/commit/1aa922f7007afe71e0b58b0c3bd0833a53cb945c (v2.3.411)
- https://github.com/PCSX2/pcsx2/commit/8eb46b5a4c0380d59cb540f8b5f59daf8e609bd7 (v2.3.414)
- https://github.com/PCSX2/pcsx2/pull/12823
- https://github.com/PCSX2/pcsx2/pull/12826