Use After Free Vulnerability in Radare2 by Radareorg
CVE-2022-28071

7.5HIGH

Key Information:

Vendor

Radare

Status
Vendor
CVE Published:
22 August 2023

What is CVE-2022-28071?

A use after free condition exists in the r_reg_get_name_idx function of Radare2, specifically affecting versions 5.4.0 and 5.4.2. This vulnerability arises when the function attempts to access freed memory, which can lead to unpredictable behavior and potential exploitation. It is crucial for users of the affected versions to apply the necessary fixes to protect their systems from potential attacks that exploit this flaw.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.