CVE-2015-8972: GNU Chess

Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers to execute arbitrary code via a large input, as demonstrated when in UCI mode.

Affected products

  • GNU Chess: before 6.2.4 (fixed in 6.2.4)

Published 2017-01-23. Last modified 2026-06-17.