---
id: CVE-2025-5222
title: >-
  A stack buffer overflow was found in Internationl components for unicode (ICU
  )
summary: >-
  A stack buffer overflow was found in Internationl components for unicode (ICU
  ). While running the genrb binary, the 'subtag' struct overflowed at the
  SRBRoot::addTag function. This issue may lead to memory corruption and local
  arbitrary…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-120
vendor: unicode
product: international_components_for_unicode
affected:
  - international_components_for_unicode < 77.1
patched:
  - international_components_for_unicode 77.1
published: '2025-05-27'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T19:16:36.083'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-5222'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:11888'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:12083'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:12331'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:12332'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:12333'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:54544'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:54553'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:54581'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:56786'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:56853'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:56911'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60019'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:65839'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-5222'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2368600'
    label: secalert@redhat.com
  - url: >-
      https://unicode-org.atlassian.net/jira/software/c/projects/ICU/issues/ICU-22957
    label: secalert@redhat.com
  - url: 'https://lists.debian.org/debian-lts-announce/2025/06/msg00015.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-585531.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5222.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-5222'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-5222'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-05-28T13:49:29.931272Z'
epss: 0.00425
epssPercentile: 0.34054
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/berkley4/icu-74-debian'
  checkedAt: '2026-09-25T08:20:46.029Z'
exploitAvailable: true
ingestedAt: '2026-06-29T13:24:34.345Z'
---

## Overview

A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.

## Affected

- `international_components_for_unicode < 77.1`

## Remediation

Upgrade past the affected range:

- `international_components_for_unicode 77.1`

## Vendor advisories

- **RHSA-2026:65839** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:65839)
- **RHSA-2026:56786** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:56786)
- **RHSA-2026:56911** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.15 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:56911)
- **RHSA-2026:56853** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:56853)
- **RHSA-2026:60019** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.17 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:60019)
- **RHSA-2026:54544** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2026-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:54544)
- **RHSA-2026:54553** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2026-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:54553)
- **RHSA-2026:54581** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.20 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:54581)
- **RHSA-2025:11888** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10) · released 2025-07-28 · [advisory](https://access.redhat.com/errata/RHSA-2025:11888)
- **RHSA-2025:12333** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.0), Red Hat Enterprise Linux BaseOS E4S (v.9.0) · released 2025-07-31 · [advisory](https://access.redhat.com/errata/RHSA-2025:12333)
- **RHSA-2025:12331** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2), Red Hat Enterprise Linux BaseOS E4S (v.9.2) · released 2025-07-31 · [advisory](https://access.redhat.com/errata/RHSA-2025:12331)
- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5222.json)
