Out-of-bounds read in radare2 - #VU142711

 

Out-of-bounds read in radare2 - #VU142711

Published: August 15, 2026


Vulnerability identifier: #VU142711
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read in the Mach-O LC_DATA_IN_CODE parser when parsing a crafted Mach-O file with verbose binary parsing enabled. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.

The vulnerable code path is only executed when bin.verbose is enabled, and user interaction is required to process the crafted file.


Affected software

radare2

Remediation

Install security update from vendor's website.

radare2 - update to 6.2.0

External References

Related Security Bulletins