Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14759

Опубликовано: 05 июл. 2026
Источник: redhat
CVSS3: 3.3

Описание

A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The patch is named cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87. To fix this issue, it is recommended to deploy a patch.

A flaw was found in radareorg radare2. A local attacker can perform a manipulation in the RBinJava Line Number Table Parser component, specifically within the r_bin_java_inner_classes_attr_calc_size function. This can lead to a heap-based buffer overflow, resulting in a denial of service.

Отчет

This Low impact flaw in radare2's RBinJava Line Number Table Parser allows a local attacker to trigger a heap-based buffer overflow. By manipulating the r_bin_java_inner_classes_attr_calc_size function, an attacker can cause a denial of service. Exploitation requires local access to the system where radare2 is installed.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Low
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2497163radare2: radare2: Denial of Service via heap-based buffer overflow

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 1 месяца назад

A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The patch is named cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87. To fix this issue, it is recommended to deploy a patch.

CVSS3: 3.3
nvd
около 1 месяца назад

A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The patch is named cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87. To fix this issue, it is recommended to deploy a patch.

CVSS3: 3.3
debian
около 1 месяца назад

A security flaw has been discovered in radareorg radare2 up to 6.1.6. ...

CVSS3: 3.3
github
около 1 месяца назад

A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The patch is named cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87. To fix this issue, it is recommended to deploy a patch.

3.3 Low

CVSS3