Mach-O Metadata Parser Vulnerability in radare2 by radareorg
CVE-2026-81881

3.3LOW

Key Information:

Vendor

Radareorg

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-81881?

The radare2 framework, a UNIX-like reverse engineering tool, contains a vulnerability in its Mach-O Swift field-metadata parser prior to version 6.2.0. This flaw occurs when a relative Swift field pointer is less than the field-metadata section base, leading to the creation of a negative logical index during subtraction. Attackers could exploit this by providing a malicious Mach-O file for parsing, resulting in incorrect metadata processing or potentially causing a process termination. However, no observable memory disclosure related to this issue has been reported. The vulnerability has been addressed in version 6.2.0.

Affected Version(s)

radare2 < 6.2.0

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.