Excessive Iteration in radare2 - #VU142707
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to excessive iteration in the Apple Preferred Executable Format (PEF) loader when parsing a crafted PEF file during file opening or inspection. A remote attacker can supply a specially crafted PEF file to cause a denial of service.
The issue is reachable through normal binary-format auto-detection, and user interaction is required to open or inspect the crafted file.