rpm package
opensuse/radare2&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/radare2&distro=openSUSE%20Leap%2016.0
Vulnerabilities (20)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-81886 | Med | 5.5 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 parser used an input-controlled physical-memory-run PageCount directly as the bound of a per-pa | |
| CVE-2026-81885 | Med | 5.5 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation fixup-chain parser was vulnerable because the NE relocation parser followed fixup chains without an active iteration limit or cycle detection. The vulnerability | |
| CVE-2026-81884 | Low | 2.5 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted dataoff and datasize and allowed a final partial record to be processed. The vul | |
| CVE-2026-81883 | Low | 3.3 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecode function parser was vulnerable because the Lua 5.3 bytecode function parser read fixed function-metadata fields immediately after a function-name string witho | |
| CVE-2026-81882 | Low | 3.3 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser underallocated an uninitialized UTF-8 destination and did not guarantee NUL | |
| CVE-2026-81881 | Low | 3.3 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata section base, making subtraction produce a nega | |
| CVE-2026-81880 | Med | 5.5 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader accepted relocSecCount values that were not bounded by the number of sections or complete reloca | |
| CVE-2026-81879 | Med | 5.5 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM handling was vulnerable because the ELF parser allocated the program-header array using the resolved PN_XNUM count but several consumers still iterated with the or | |
| CVE-2026-81878 | Med | 5.5 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal readers accepted a 32-bit string length without rejecting values that overflow the size-plus-on | |
| CVE-2026-14788 | Low | 3.3 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Jul 6, 2026 | A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been dis | |
| CVE-2026-14761 | Low | 3.3 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Jul 5, 2026 | A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is the function r_str_ndup/r_str_append of the file libr/util/str.c. The manipulation leads to integer overflow. An attack has to be approached locally. The exploit has been disclose | |
| CVE-2026-14760 | Low | 3.3 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Jul 5, 2026 | A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit h | |
| CVE-2026-14759 | Low | 3.3 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Jul 5, 2026 | A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer o | |
| CVE-2026-14758 | Low | 3.3 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Jul 5, 2026 | A vulnerability was identified in radareorg radare2 up to 6.1.6. This vulnerability affects the function cmd_anal_opcode of the file libr/core/cmd_anal.inc.c of the component hexpairs Parser. Such manipulation leads to integer overflow. The attack needs to be performed locally. T | |
| CVE-2026-14757 | Med | 5.3 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Jul 5, 2026 | A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be ut | |
| CVE-2026-8695 | Hig | 7.5 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | May 15, 2026 | radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability thr | |
| CVE-2026-40517 | Hig | 7.8 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Apr 22, 2026 | radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by crafting a malicious PDB file with newline characters in symbol names. Attackers can inject arbitrary radare2 comman | |
| CVE-2026-40527 | Hig | 7.8 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Apr 17, 2026 | radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can craft a binary with shell commands in DWARF paramete | |
| CVE-2026-41015 | Hig | 7.4 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Apr 16, 2026 | radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6 | |
| CVE-2026-4174 | Low | 3.3 | < 6.2.2-bp160.1.1 | 6.2.2-bp160.1.1 | Mar 16, 2026 | A vulnerability has been found in Radare2 5.9.9. This issue affects the function walk_exports_trie of the file libr/bin/format/mach0/mach0.c of the component Mach-O File Parser. Such manipulation leads to resource consumption. The attack can only be performed from a local environ |
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 parser used an input-controlled physical-memory-run PageCount directly as the bound of a per-pa
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation fixup-chain parser was vulnerable because the NE relocation parser followed fixup chains without an active iteration limit or cycle detection. The vulnerability
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted dataoff and datasize and allowed a final partial record to be processed. The vul
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecode function parser was vulnerable because the Lua 5.3 bytecode function parser read fixed function-metadata fields immediately after a function-name string witho
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser underallocated an uninitialized UTF-8 destination and did not guarantee NUL
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata section base, making subtraction produce a nega
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader accepted relocSecCount values that were not bounded by the number of sections or complete reloca
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM handling was vulnerable because the ELF parser allocated the program-header array using the resolved PN_XNUM count but several consumers still iterated with the or
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal readers accepted a 32-bit string length without rejecting values that overflow the size-plus-on
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been dis
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is the function r_str_ndup/r_str_append of the file libr/util/str.c. The manipulation leads to integer overflow. An attack has to be approached locally. The exploit has been disclose
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit h
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer o
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
A vulnerability was identified in radareorg radare2 up to 6.1.6. This vulnerability affects the function cmd_anal_opcode of the file libr/core/cmd_anal.inc.c of the component hexpairs Parser. Such manipulation leads to integer overflow. The attack needs to be performed locally. T
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be ut
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability thr
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by crafting a malicious PDB file with newline characters in symbol names. Attackers can inject arbitrary radare2 comman
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can craft a binary with shell commands in DWARF paramete
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6
- affected < 6.2.2-bp160.1.1fixed 6.2.2-bp160.1.1
A vulnerability has been found in Radare2 5.9.9. This issue affects the function walk_exports_trie of the file libr/bin/format/mach0/mach0.c of the component Mach-O File Parser. Such manipulation leads to resource consumption. The attack can only be performed from a local environ