Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40499

Опубликовано: 15 апр. 2026
Источник: debian
EPSS Низкий

Описание

radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially crafted section names to inject r2 commands that are executed when the idp command processes the file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
radare2fixed6.1.4+ds-1experimentalpackage
radare2fixed6.1.6+ds-2package

Примечания

  • https://github.com/radareorg/radare2/pull/25731

  • https://github.com/radareorg/radare2/issues/25752

  • Fixed by: https://github.com/radareorg/radare2/commit/5590c87deeb7eb2a106fd7aab9ca88bfeebb7397 (6.1.4)

EPSS

Процентиль: 65%
0.01184
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
4 месяца назад

radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially crafted section names to inject r2 commands that are executed when the idp command processes the file.

CVSS3: 7.8
nvd
4 месяца назад

radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially crafted section names to inject r2 commands that are executed when the idp command processes the file.

CVSS3: 7.8
github
4 месяца назад

radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially crafted section names to inject r2 commands that are executed when the idp command processes the file.

suse-cvrf
4 месяца назад

Security update for radare2

EPSS

Процентиль: 65%
0.01184
Низкий
Уязвимость CVE-2026-40499