A stack-based buffer overflow vulnerability was detected in radareorg radare2 up to 6.1.6, affecting the Memory64ListStream Parser in the file libr/bin/format/mdmp/mdmp.c. The vulnerability requires a local approach and has a CVSS score of 1.9, classified as LOW severity. The exploit is public, and a patch is available. Users of radare2 version 6.1.6 or earlier should be aware of this vulnerability and ta [truncated]
A weakness has been identified in radareorg radare2 up to 6.1.6, specifically in the cmd_print function of the libr/core/cmd_print.inc library, which is part of the pb Print Command Handler component. This manipulation causes an integer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch name: 2b6265476c75567006b0fcbb749 [truncated]
A use after free vulnerability was identified in radare2, a reverse engineering framework, in the regprofile handler. The vulnerability exists in the r_core_seek_arch_bits function of the libr/core/disasm.c file. Local access is required to exploit this vulnerability. The attack requires specific conditions to be met, and a patch has been made available to correct this issue. Users of radare2 should be aw [truncated]
CVE-2026-14757 is an integer overflow vulnerability in Radare2 up to 6.1.6. The vulnerability affects the core_anal_bytes function in libr/core/cmd_anal.inc and requires local access to be exploited. This issue allows local attackers to potentially exploit the vulnerability. The CVE record was published on 2026-07-05T15:16:56.810Z and was last modified on 2026-07-07T22:46:20.453Z. Users of Radare2 up to v [truncated]