CVE-2025-15382: Memmove Shift Overread Dest Length

A buffer shift operation was detected that uses the destination offset directly in length calculations ($SZ - $DST). This can cause a heap over-read by moving more bytes than are remaining at the source offset. When shifting left (e.g., removing a substring), the length must be calculated relative to the source pointer or explicitly bounded, otherwise bytes

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0C
greprules fetch cve-2025-15382-memmove-shift-overread-dest-length --engine opengrep

Description

A buffer shift operation was detected that uses the destination offset directly in length calculations ($SZ - $DST). This can cause a heap over-read by moving more bytes than are remaining at the source offset. When shifting left (e.g., removing a substring), the length must be calculated relative to the source pointer or explicitly bounded, otherwise bytes