VYPR

rpm package

opensuse/radare2&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/radare2&distro=openSUSE%20Leap%2016.0

Vulnerabilities (20)

  • CVE-2026-81886MedSep 22, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 parser used an input-controlled physical-memory-run PageCount directly as the bound of a per-pa

  • CVE-2026-81885MedSep 22, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation fixup-chain parser was vulnerable because the NE relocation parser followed fixup chains without an active iteration limit or cycle detection. The vulnerability

  • CVE-2026-81884LowSep 22, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted dataoff and datasize and allowed a final partial record to be processed. The vul

  • CVE-2026-81883LowSep 22, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecode function parser was vulnerable because the Lua 5.3 bytecode function parser read fixed function-metadata fields immediately after a function-name string witho

  • CVE-2026-81882LowSep 22, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser underallocated an uninitialized UTF-8 destination and did not guarantee NUL

  • CVE-2026-81881LowSep 22, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata section base, making subtraction produce a nega

  • CVE-2026-81880MedSep 22, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader accepted relocSecCount values that were not bounded by the number of sections or complete reloca

  • CVE-2026-81879MedSep 22, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM handling was vulnerable because the ELF parser allocated the program-header array using the resolved PN_XNUM count but several consumers still iterated with the or

  • CVE-2026-81878MedSep 22, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal readers accepted a 32-bit string length without rejecting values that overflow the size-plus-on

  • CVE-2026-14788LowJul 6, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been dis

  • CVE-2026-14761LowJul 5, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is the function r_str_ndup/r_str_append of the file libr/util/str.c. The manipulation leads to integer overflow. An attack has to be approached locally. The exploit has been disclose

  • CVE-2026-14760LowJul 5, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit h

  • CVE-2026-14759LowJul 5, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer o

  • CVE-2026-14758LowJul 5, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    A vulnerability was identified in radareorg radare2 up to 6.1.6. This vulnerability affects the function cmd_anal_opcode of the file libr/core/cmd_anal.inc.c of the component hexpairs Parser. Such manipulation leads to integer overflow. The attack needs to be performed locally. T

  • CVE-2026-14757MedJul 5, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be ut

  • CVE-2026-8695HigMay 15, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability thr

  • CVE-2026-40517HigApr 22, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by crafting a malicious PDB file with newline characters in symbol names. Attackers can inject arbitrary radare2 comman

  • CVE-2026-40527HigApr 17, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can craft a binary with shell commands in DWARF paramete

  • CVE-2026-41015HigApr 16, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6

  • CVE-2026-4174LowMar 16, 2026
    affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1

    A vulnerability has been found in Radare2 5.9.9. This issue affects the function walk_exports_trie of the file libr/bin/format/mach0/mach0.c of the component Mach-O File Parser. Such manipulation leads to resource consumption. The attack can only be performed from a local environ