CVE-2025-6141
Publication date 16 June 2025
Last updated 1 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.
Read the notes from the security team
Why is this CVE low priority?
no security impact as terminfo files are trusted
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| ncurses | 26.04 LTS resolute |
Not affected
|
| 24.04 LTS noble |
Fixed 6.4+20240113-1ubuntu2.2
|
|
| 22.04 LTS jammy |
Fixed 6.3-2ubuntu0.3
|
|
| 20.04 LTS focal |
Fixed 6.2-0ubuntu2.1+esm2
|
|
| 18.04 LTS bionic |
Fixed 6.1-1ubuntu1.18.04.1+esm4
|
|
| 16.04 LTS xenial |
Fixed 6.0+20160213-1ubuntu1+esm7
|
|
| 14.04 LTS trusty |
Fixed 5.9+20140118-1ubuntu1+esm7
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialNotes
mdeslaur
This is in the code that parses terminfo database files. terminfo files are normally trusted, and since the fix for CVE-2023-29491, we no longer parse terminfo files when apps are setuid. As such, this doesn't really have a security impact. Setting priority to low.
Severity score breakdown
CVSS version:
Base score
4.8 · Medium
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Base score
3.3 · Low
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
References
Related Ubuntu Security Notices (USN)
- USN-8709-1
- ncurses vulnerability
- 1 September 2026
Other references
- https://www.cve.org/CVERecord?id=CVE-2025-6141
- https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html
- https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html
- https://invisible-island.net/ncurses/NEWS.html#index-t20250329
- https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html
- https://vuldb.com/?ctiid.312610
- https://vuldb.com/?id.312610
- https://vuldb.com/?submit.593000