PatchSiren cyber security CVE debrief
CVE-2026-81883 radareorg CVE debrief
A vulnerability in radare2's Lua 5.3 bytecode function parser can cause invalid parser results or process termination when opening or inspecting a crafted Lua 5.3 bytecode file. The vulnerability is triggered by a function-name string that ends at the input-buffer boundary, causing the parser to read beyond the allocated buffer. This issue is fixed in version 6.2.0. Defenders should be aware of the potential for process instability and incorrect analysis results when handling untrusted Lua 5.3 bytecode files.
- Vendor
- radareorg
- Product
- radare2
- CVSS
- LOW 3.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for radare2 installations, particularly those handling untrusted Lua 5.3 bytecode files, should assess exposure and prioritize updates to 6.2.0 or later. This includes operators, platform administrators, vulnerability management teams, and security teams who need to ensure the integrity and availability of radare2 processes and analysis results.
Why it matters
Defenders should care about CVE-2026-81883 because it affects radare2's Lua 5.3 bytecode function parser, potentially causing process termination or invalid parser results when handling crafted files. Those responsible for radare2 installations, especially in environments handling untrusted bytecode files, should assess exposure and prioritize updating to version 6.2.0 or later. The vulnerability's impact is limited to availability and integrity of the radare2 process, with no demonstrated memory disclosure. Verification of radare2 versions and monitoring for suspicious activity are recommended.
- Process termination or instability
- Invalid parser results potentially leading to incorrect analysis
- Need for verification of radare2 versions and updates
- Potential for denial of service through crafted files
Technical summary
The radare2 Lua 5.3 bytecode function parser vulnerability occurs when parsing a crafted Lua 5.3 bytecode file. The parser reads fixed function-metadata fields immediately after a function-name string without checking the remaining buffer length. This can lead to process termination or invalid parser results. The vulnerability is triggered by a function-name string that ends at the input-buffer boundary, causing the parser to read two integers and three one-byte fields beyond the allocated input buffer. No attacker-observable memory disclosure has been demonstrated.
Defensive priority
Defenders should prioritize verifying radare2 versions and updating to 6.2.0 or later to address this vulnerability.
Recommended defensive actions
- Verify radare2 versions in use and update to 6.2.0 or later
- Review and restrict access to untrusted Lua 5.3 bytecode files
- Monitor radare2 installations for suspicious activity
- Perform a thorough review of the environment for potential exposure
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions and retest remediated assets
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability is triggered by opening or inspecting a crafted Lua 5.3 bytecode file whose function-name string ends at the input-buffer boundary. The parser read two integers and three one-byte fields beyond the allocated input buffer.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-81883 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-81883
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-81883 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81883
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/radareorg/radare2/commit/26c2eac360033458e9d266e5e30667d1f8d642e3
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/radareorg/radare2/issues/26228
[email protected] - Exploit, Issue Tracking, Mitigation, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/radareorg/radare2/releases/tag/6.2.0
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/radareorg/radare2/security/advisories/GHSA-96m5-hvwp-674c
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.