Buffer Overflow Vulnerability in radare2’s PEF Loader
CVE-2026-81880

5.5MEDIUM

Key Information:

Vendor

Radareorg

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-81880?

The radare2 reverse engineering framework is susceptible to a buffer overflow in its Apple Preferred Executable Format (PEF) loader before version 6.2.0. Specifically, the loader improperly handles relocSecCount values, leading to potential denial of service through excessive CPU usage as it may loop through up to 268,435,456 relocation-section iterations. This condition arises with crafted Apple PEF files during standard binary-format auto-detection, allowing the process to exceed valid buffer boundaries, consequently resulting in significant resource consumption and extended processing times. Upgrade to radare2 version 6.2.0 to mitigate this issue.

Affected Version(s)

radare2 < 6.2.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.