Out-of-bounds read in radare2 - #VU142705

 

Out-of-bounds read in radare2 - #VU142705

Published: August 15, 2026


Vulnerability identifier: #VU142705
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read in the Mach-O Swift field metadata parser when parsing a crafted Swift Mach-O file. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.

The vulnerable path is reached while parsing Swift type and class metadata, and user interaction is required to analyze the crafted file.


Affected software

radare2

Remediation

Install security update from vendor's website.

radare2 - update to 6.2.0

External References

Related Security Bulletins