Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14760

Опубликовано: 05 июл. 2026
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.

A flaw was found in radareorg radare2. This vulnerability, a use-after-free, affects the regprofile Handler component. A local attacker can exploit this flaw by performing a specific manipulation, which could lead to a denial of service, making the application unavailable.

Отчет

This flaw is rated as Low impact due to its requirement for local access to trigger a use-after-free vulnerability within the radare2 reverse engineering framework. Exploitation could result in a denial of service, impacting the availability of the application. The limited scope of this vulnerability, primarily affecting users who execute radare2 locally, contributes to its lower severity.

Меры по смягчению последствий

To mitigate this issue, restrict local access to systems where radare2 is installed. If radare2 is not essential for system operation, consider removing the radare2 package to eliminate the vulnerability.

Дополнительная информация

Статус:

Low
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2497162radare2: radare2: Denial of Service via local use-after-free vulnerability

EPSS

Процентиль: 6%
0.00166
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 1 месяца назад

A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.

CVSS3: 3.3
nvd
около 1 месяца назад

A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.

CVSS3: 3.3
debian
около 1 месяца назад

A weakness has been identified in radareorg radare2 up to 6.1.6. Impac ...

CVSS3: 3.3
github
около 1 месяца назад

A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.

EPSS

Процентиль: 6%
0.00166
Низкий

3.3 Low

CVSS3