Junglewise Threat Intelligence

CVE-2026-14759: radareorg radare2 heap overflow in RBinJava Line Number Table Parser

CVE-2026-14759 · Severity: low · CVSS 3.3 · Published 2026-07-05

Executive brief

radare2 is a popular open-source framework used by security researchers and developers for reverse engineering and analyzing software. A vulnerability in its Java class file parser could allow a local attacker to cause the application to crash by providing a specially crafted file. This impact is primarily limited to service availability for the user performing the analysis.

Technical details

A heap-based buffer overflow (specifically an out-of-bounds read) exists in radare2 up to version 6.1.6 within the RBinJava component. The vulnerability is located in the r_bin_java_line_number_table_attr_new function (shlr/java/class.c), where the parser fails to sufficiently validate the size of the Line Number Table attribute buffer. Specifically, the code attempted to read an 8-byte structure from a buffer that could be as small as 6 bytes. A local attacker can exploit this by providing a malformed Java class file, leading to an application crash. A patch (commit cd62d15) has been released to increase the minimum size check from 6 to 8 bytes.

Affected products

  • radareorg radare2 up to 6.1.6

Timeline

  • 2026-06-04: disclosed: Issue reported on GitHub
  • 2026-07-05: advisory: CVE-2026-14759 published
  • 2026-07-05: patched: Patch commit cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87 identified

References