CVE-2025-69720: Buffer Overflow

Published Mar 19, 2026
·
Updated

Last updated 2 April 2026

Other sources

ncurses v6.5 and v6.4 are vulnerable to Buffer Overflow in progs/infocmp.c, function analyzestring().

Red Hat

The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyzestring in progs/infocmp.c.

MITRE

Affected Software

87 affected componentsFixes available
ncurses infocmp (ncurses)<6.5-20251213, =6.5, =6.4
Microsoft azl3 ncurses 6.4-2
Microsoft cbl2 ncurses 6.4-3
Microsoft azl3 ncurses 6.4-3
invisible-island Ncurses<=6.4
invisible-island Ncurses=6.5-20240427
invisible-island Ncurses=6.5-20240504
invisible-island Ncurses=6.5-20240511
invisible-island Ncurses=6.5-20240518
invisible-island Ncurses=6.5-20240519
invisible-island Ncurses=6.5-20240525
invisible-island Ncurses=6.5-20240601
invisible-island Ncurses=6.5-20240608
invisible-island Ncurses=6.5-20240615
invisible-island Ncurses=6.5-20240622
invisible-island Ncurses=6.5-20240629
invisible-island Ncurses=6.5-20240706
invisible-island Ncurses=6.5-20240713
invisible-island Ncurses=6.5-20240720
invisible-island Ncurses=6.5-20240727
invisible-island Ncurses=6.5-20240810
invisible-island Ncurses=6.5-20240817
invisible-island Ncurses=6.5-20240824
invisible-island Ncurses=6.5-20240831
invisible-island Ncurses=6.5-20240914
invisible-island Ncurses=6.5-20240922
invisible-island Ncurses=6.5-20240928
invisible-island Ncurses=6.5-20241006
invisible-island Ncurses=6.5-20241019
invisible-island Ncurses=6.5-20241026
invisible-island Ncurses=6.5-20241102
invisible-island Ncurses=6.5-20241109
invisible-island Ncurses=6.5-20241123
invisible-island Ncurses=6.5-20241130
invisible-island Ncurses=6.5-20241207
invisible-island Ncurses=6.5-20241214
invisible-island Ncurses=6.5-20241221
invisible-island Ncurses=6.5-20241228
invisible-island Ncurses=6.5-20250104
invisible-island Ncurses=6.5-20250111
invisible-island Ncurses=6.5-20250118
invisible-island Ncurses=6.5-20250125
invisible-island Ncurses=6.5-20250201
invisible-island Ncurses=6.5-20250208
invisible-island Ncurses=6.5-20250215
invisible-island Ncurses=6.5-20250216
invisible-island Ncurses=6.5-20250222
invisible-island Ncurses=6.5-20250301
invisible-island Ncurses=6.5-20250308
invisible-island Ncurses=6.5-20250315
invisible-island Ncurses=6.5-20250322
invisible-island Ncurses=6.5-20250329
invisible-island Ncurses=6.5-20250405
invisible-island Ncurses=6.5-20250412
invisible-island Ncurses=6.5-20250419
invisible-island Ncurses=6.5-20250426
invisible-island Ncurses=6.5-20250503
invisible-island Ncurses=6.5-20250510
invisible-island Ncurses=6.5-20250517
invisible-island Ncurses=6.5-20250524
invisible-island Ncurses=6.5-20250531
invisible-island Ncurses=6.5-20250614
invisible-island Ncurses=6.5-20250621
invisible-island Ncurses=6.5-20250628
invisible-island Ncurses=6.5-20250705
invisible-island Ncurses=6.5-20250712
invisible-island Ncurses=6.5-20250720
invisible-island Ncurses=6.5-20250726
invisible-island Ncurses=6.5-20250802
invisible-island Ncurses=6.5-20250809
invisible-island Ncurses=6.5-20250816
invisible-island Ncurses=6.5-20250823
invisible-island Ncurses=6.5-20250830
invisible-island Ncurses=6.5-20250913
invisible-island Ncurses=6.5-20250920
invisible-island Ncurses=6.5-20250927
invisible-island Ncurses=6.5-20251004
invisible-island Ncurses=6.5-20251010
invisible-island Ncurses=6.5-20251018
invisible-island Ncurses=6.5-20251025
invisible-island Ncurses=6.5-20251101
invisible-island Ncurses=6.5-20251115
invisible-island Ncurses=6.5-20251122
invisible-island Ncurses=6.5-20251123
invisible-island Ncurses=6.5-20251129
invisible-island Ncurses=6.5-20251206
debian/ncurses<=6.2+20201114-2+deb11u2, <=6.4-4, <=6.5+20250216-2
6.6+20251231-16.6+20260608-2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/ncurses to a version that resolves this vulnerability.

    Fixed in 6.6+20251231-1Fixed in 6.6+20260608-2
  2. Upgrade

    Upgrade ncurses to a version that resolves this vulnerability.

    Fixed in 6.5-20251213
  3. Upgrade

    Upgrade ncurses to a version that resolves this vulnerability.

    Fixed in 6.4

Event History

Mar 19, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·03:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Mar 25, 2026
Data Sourced
via Microsoft·08:04 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:04 AM
Affected Software
Updated
via Microsoft·08:04 AM
Severity
Jul 3, 2026
Data Sourced
via Ubuntu·02:21 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·02:22 PM
DescriptionAffected Software
Data Sourced
via Launchpad·02:22 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-69720?

CVE-2025-69720 has a critical severity due to the potential for remote code execution through buffer overflow.

2

How do I fix CVE-2025-69720?

To fix CVE-2025-69720, update ncurses to version 6.5-20251213 or later.

3

What versions of ncurses are affected by CVE-2025-69720?

CVE-2025-69720 affects ncurses versions 6.4 and 6.5 up to 6.5-20251212.

4

What is the nature of the vulnerability in CVE-2025-69720?

CVE-2025-69720 is a buffer overflow vulnerability found in the analyze_string function of the infocmp tool.

5

Is there a workaround for CVE-2025-69720 while I wait for a patch?

A potential workaround is to avoid using the infocmp command until the patch is applied, though this may limit functionality.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203