Heap Out-of-Bounds Vulnerability in radare2 Command-Line Tool
CVE-2026-81884

2.5LOW

Key Information:

Vendor

Radareorg

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-81884?

The radare2 reverse engineering framework contains a vulnerability in its Mach-O LC_DATA_IN_CODE parser prior to version 6.2.0. This flaw arises from improper handling of the 'dataoff' and 'datasize' parameters, which can lead to reading beyond allocated memory bounds when processing specially crafted Mach-O files. When a file is opened with the non-default bin.verbose option enabled, if the 'datasize' does not align properly with expected values, the parser may access out-of-bounds memory, potentially resulting in termination of the process. While this issue does not currently present observable memory disclosure risks, it is essential to update to version 6.2.0 or later to mitigate this vulnerability.

Affected Version(s)

radare2 < 6.2.0

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.