PatchSiren

rizinorg CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM rizinorg CVE published 2026-07-16

CVE-2026-45612

The CVE-2026-45612 vulnerability affects the rz-libdemangle Rizin library, specifically the Rust demangler in src/rust/rust_v0.c. An out-of-bounds read can occur when the demangler structure is not yet initialized. This issue was fixed in commit 6bf56d3. The rz-libdemangle library is used for demangling symbols in Rizin and has a vulnerability in its Rust demangler. The vulnerability can lead to potential [truncated]

LOW rizinorg CVE published 2026-05-29

CVE-2026-45613

A heap-buffer-overflow vulnerability exists in Rizin, a UNIX-like reverse engineering framework and command-line toolset. The flaw is located in the OMF (Object Module Format) binary parser at librz/bin/format/omf/omf.c. The vulnerability has been assigned a CVSS 3.1 score of 3.3 (Low severity), indicating limited impact due to local attack vector requirements and user interaction needed for exploitation. [truncated]

LOW rizinorg CVE published 2026-05-29

CVE-2026-45324

A double-free vulnerability exists in Rizin, a UNIX-like reverse engineering framework. The flaw occurs in the `byte_pattern_search()` function within `librz/core/cmd/cmd_search.c` due to incorrect pointer ownership semantics. An attacker with local access could potentially trigger memory corruption, leading to limited integrity and availability impact. The vulnerability requires high attack complexity, p [truncated]