PatchSiren cyber security CVE debrief
CVE-2026-14789 radareorg CVE debrief
A stack-based buffer overflow vulnerability was detected in radareorg radare2 up to 6.1.6, affecting the Memory64ListStream Parser in the file libr/bin/format/mdmp/mdmp.c. The vulnerability requires a local approach and has a CVSS score of 1.9, classified as LOW severity. The exploit is public, and a patch is available. Users of radare2 version 6.1.6 or earlier should be aware of this vulnerability and take steps to mitigate it. The vulnerability is caused by a stack-based buffer overflow in the Memory64ListStream Parser.
- Vendor
- radareorg
- Product
- radare2
- CVSS
- LOW 1.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-06
- Original CVE updated
- 2026-07-09
- Advisory published
- 2026-07-06
- Advisory updated
- 2026-07-09
Who should care
Users of radare2 version 6.1.6 or earlier should be aware of this vulnerability and take steps to mitigate it. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess the impact of this vulnerability on their deployments and plan accordingly.
Technical summary
The vulnerability is caused by a stack-based buffer overflow in the Memory64ListStream Parser in the file libr/bin/format/mdmp/mdmp.c of radareorg radare2 up to 6.1.6. The attack requires a local approach and the exploit is now public. The patch is named 175d4addb68981331c85b10681c2161c38fb5762. Users should apply the patch or update radare2 to a version beyond 6.1.6. The vulnerability has a CVSS score of 1.9 and is classified as LOW severity.
Defensive priority
Low priority, as the vulnerability requires a local approach and has a low CVSS score.
Recommended defensive actions
- Apply the patch 175d4addb68981331c85b10681c2161c38fb5762 to address the vulnerability.
- Update radare2 to a version beyond 6.1.6.
- Monitor for and track any potential exploits or attacks.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record was published on 2026-07-06T03:16:29.220Z and last modified on 2026-07-09T15:09:39.300Z. The NVD entry is currently Analyzed. The vulnerability affects radareorg radare2 up to 6.1.6, specifically the Memory64ListStream Parser in the file libr/bin/format/mdmp/mdmp.c. The attack requires a local approach. The exploit is now public and may be used. The patch is named 175d4addb68981331c85b10681c2161c38fb5762. Users should verify their deployments and consider mitigation strategies.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-14789 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-14789
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-14789 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14789
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/mengzhisuoliu/radare2/commit/175d4addb68981331c85b10681c2161c38fb5762
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/radareorg/radare2/
[email protected] - Product
-
Source reference
Unverified legacy reference
URL: https://github.com/radareorg/radare2/issues/26051
[email protected] - Exploit, Issue Tracking
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-14789
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/submit/850389
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/vuln/376378
[email protected] - Third Party Advisory, VDB Entry
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/376378/cti
[email protected] - Permissions Required, VDB Entry
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.