Memory Consumption Vulnerability in radare2's Windows 64-bit DMP Parser
CVE-2026-81886

5.5MEDIUM

Key Information:

Vendor

Radareorg

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-81886?

A vulnerability exists in the radare2 Windows 64-bit crash-dump parser, allowing the opening of a specially crafted full-memory Windows crash dump to trigger excessive memory allocation. The parser's failure to validate the input-controlled PageCount against the actual dump size leads to unbounded memory consumption, potentially causing a denial of service due to resource exhaustion. This issue has been resolved in version 6.2.0.

Affected Version(s)

radare2 < 6.2.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.