VYPR
High severity7.8OSV Advisory· Published Dec 23, 2024· Updated Jun 17, 2026

CVE-2024-53256

CVE-2024-53256

Description

Rizin is a UNIX-like reverse engineering framework and command-line toolset. rizin.c still had an old snippet of code which suffered a command injection due the usage of rz_core_cmdf to invoke the command m which was removed in v0.1.x. A malicious binary defining bclass (part of RzBinInfo) is executed if rclass (part of RzBinInfo) is set to fs; the vulnerability can be exploited by any bin format where bclass and rclass are user defined. This vulnerability is fixed in 0.7.4.

Affected products

2
  • Rizin/RizinOSV2 versions
    0.1.0, v0.1.0, v0.1.1, …+ 1 more
    • (no CPE)range: 0.1.0, v0.1.0, v0.1.1, …
    • (no CPE)range: <0.7.4

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.