PatchSiren cyber security CVE debrief
CVE-2026-81886 radareorg CVE debrief
CVE-2026-81886 is a vulnerability in radare2, a UNIX-like reverse engineering framework and command-line toolset. The vulnerability is in the Windows 64-bit crash-dump dmp64 parser, which can be triggered by opening a small crafted full-memory Windows crash dump, leading to denial of service through excessive memory consumption and processing time. This issue is fixed in version 6.2.0.
- Vendor
- radareorg
- Product
- radare2
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-09-28
Who should care
Defenders who use radare2 for reverse engineering and vulnerability analysis should care about this vulnerability because it can lead to denial of service attacks. They should prioritize updating radare2 to version 6.2.0 or later to prevent such attacks. Additionally, defenders responsible for system resources and monitoring should be aware of the potential for excessive memory consumption and processing time, and review compensating controls for exposed
Why it matters
CVE-2026-81886 is a vulnerability in radare2 that can lead to denial of service attacks. Defenders should prioritize updating radare2 to version 6.2.0 or later to prevent such attacks.
- Denial of service through excessive memory consumption and processing time
- Potential for system crashes or freezes
- Need for increased monitoring of system resources
Technical summary
The vulnerability is in the Windows 64-bit crash-dump dmp64 parser of radare2, a UNIX-like reverse engineering framework and command-line toolset. This parser can be triggered by opening a small crafted full-memory Windows crash dump, leading to denial of service through excessive memory consumption and processing time. The issue arises because the parser uses an input-controlled physical-memory-run PageCount directly as the bound of a per-page allocation loop, repeatedly allocating and appending page descriptors without validating the count against the dump size. This can cause system crashes or freezes and requires defenders to prioritize updating radare2 to version 6.2.0 or later.
Defensive priority
Defenders should prioritize updating radare2 to version 6.2.0 or later to prevent denial of service attacks.
Recommended defensive actions
- Update radare2 to version 6.2.0 or later
- Restrict access to crafted full-memory Windows crash dumps
- Monitor system resources for excessive memory consumption and processing time
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is caused by the Windows dmp64 parser using an input-controlled physical-memory-run PageCount directly as the bound of a per-page allocation loop. The parser repeatedly allocated and appended page descriptors without validating the count against the dump size. This issue can be triggered by opening a small crafted full-memory Windows crash dump, leading to denial of service through excessive memory consumption and processing time. Defenders should verify the patch version and review system resources for signs of the
Sources and references
Verified primary and authoritative sources
-
CVE-2026-81886 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-81886
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-81886 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81886
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/radareorg/radare2/commit/a7519fdb4da6835c2cecd8fe248e7dd1133cf17a
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/radareorg/radare2/issues/26224
[email protected] - Exploit, Issue Tracking, Mitigation, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/radareorg/radare2/pull/26180
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/radareorg/radare2/releases/tag/6.2.0
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/radareorg/radare2/security/advisories/GHSA-3xrx-wh64-8xr8
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.