Local Denial of Service in Radare2 by Radareorg
CVE-2024-26475
Key Information:
Badges
What is CVE-2024-26475?
A local denial of service vulnerability has been identified in Radare2 versions ranging from v0.9.7 to v5.8.6. This vulnerability originates from the grub_sfs_read_extent function, which can be exploited by an attacker with local access to the target system. Successful exploitation enables the local attacker to disrupt the availability of the affected software, significantly impairing its functionality. Users of Radare2 are advised to upgrade to version v5.8.8 or later to mitigate this issue and ensure continued service availability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
Vulnerability published
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability Reserved
