These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-81886 is a vulnerability in radare2, a UNIX-like reverse engineering framework and command-line toolset. The vulnerability is in the Windows 64-bit crash-dump dmp64 parser, which can be triggered by opening a small crafted full-memory Windows crash dump, leading to denial of service through excessive memory consumption and processing time. This issue is fixed in version 6.2.0.
CVE-2026-81885 is a denial-of-service vulnerability in radare2, a UNIX-like reverse engineering framework. The vulnerability is triggered by opening a crafted NE executable and can cause continuous CPU and memory consumption. This issue is fixed in version 6.2.0. Affected product deployments should be assessed for exposure, and owners should prioritize verification and potential upgrades to mitigate the v [truncated]
A heap out-of-bounds read vulnerability exists in radare2's Mach-O LC_DATA_IN_CODE parser prior to version 6.2.0. The vulnerability is triggered by opening a crafted Mach-O file while the non-default bin.verbose option is enabled. This can cause a process termination; however, no attacker-observable memory disclosure has been demonstrated. The vulnerability exists due to the parser trusting dataoff and da [truncated]
A vulnerability in radare2's Lua 5.3 bytecode function parser can cause invalid parser results or process termination when opening or inspecting a crafted Lua 5.3 bytecode file. The vulnerability is triggered by a function-name string that ends at the input-buffer boundary, causing the parser to read beyond the allocated buffer. This issue is fixed in version 6.2.0. Defenders should be aware of the potent [truncated]
CVE-2026-81882 is a vulnerability in radare2, a UNIX-like reverse engineering framework and command-line toolset. The vulnerability is due to a binary property-list Unicode parser underallocating an uninitialized UTF-8 destination and not guaranteeing NUL termination. This can cause disclosure of uninitialized or adjacent heap contents in JSON output and possible process termination. The issue is fixed in [truncated]
A vulnerability in radare2's Mach-O Swift field-metadata parser can cause incorrect metadata processing or process termination when parsing a crafted Mach-O file. This issue is fixed in version 6.2.0. The vulnerability occurs due to a relative Swift field pointer that could be lower than the field-metadata section base, leading to a negative logical index. This can result in incorrect metadata processing [truncated]
A crafted Apple PEF file can cause radare2 to perform excessive CPU consumption and prolonged processing due to a vulnerability in the PEF loader prior to version 6.2.0. This vulnerability is triggered by normal binary-format auto-detection of a small crafted Apple PEF file, leading to up to 268,435,456 relocation-section iterations and repeated buffer operations after record offsets pass the end of the f [truncated]
A heap out-of-bounds read vulnerability exists in radare2's ELF PN_XNUM handling prior to version 6.2.0. Processing a crafted ELF file can cause a denial of service due to process termination. The issue is fixed in version 6.2.0. This vulnerability is triggered by a specific ELF file structure, leading to a heap out-of-bounds read and process termination, which can be exploited for denial of service attac [truncated]
A vulnerability in radare2's CPython bytecode .pyc marshal parser can cause heap memory corruption and denial of service when opening or inspecting a crafted .pyc file. The vulnerability is triggered by a 32-bit string length that overflows the size-plus-one allocation, leading to potential heap memory corruption and denial of service. Defenders should prioritize verifying and updating radare2 to version [truncated]
A stack-based buffer overflow vulnerability was detected in radareorg radare2 up to 6.1.6, affecting the Memory64ListStream Parser in the file libr/bin/format/mdmp/mdmp.c. The vulnerability requires a local approach and has a CVSS score of 1.9, classified as LOW severity. The exploit is public, and a patch is available. Users of radare2 version 6.1.6 or earlier should be aware of this vulnerability and ta [truncated]
A weakness has been identified in radareorg radare2 up to 6.1.6, specifically in the cmd_print function of the libr/core/cmd_print.inc library, which is part of the pb Print Command Handler component. This manipulation causes an integer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch name: 2b6265476c75567006b0fcbb749 [truncated]
A use after free vulnerability was identified in radare2, a reverse engineering framework, in the regprofile handler. The vulnerability exists in the r_core_seek_arch_bits function of the libr/core/disasm.c file. Local access is required to exploit this vulnerability. The attack requires specific conditions to be met, and a patch has been made available to correct this issue. Users of radare2 should be aw [truncated]
CVE-2026-14757 is an integer overflow vulnerability in Radare2 up to 6.1.6. The vulnerability affects the core_anal_bytes function in libr/core/cmd_anal.inc and requires local access to be exploited. This issue allows local attackers to potentially exploit the vulnerability. The CVE record was published on 2026-07-05T15:16:56.810Z and was last modified on 2026-07-07T22:46:20.453Z. Users of Radare2 up to v [truncated]