Executive brief
A security vulnerability exists in radare2, a widely used open-source reverse engineering framework. An attacker with local access to a system could trigger a crash or cause the application to behave unexpectedly by providing specially crafted input that causes an internal calculation error. This could lead to a denial-of-service condition, impacting the availability of the tool for security researchers and developers.
Technical details
An integer overflow vulnerability exists in the `r_str_word_get0set` function within `libr/util/str.c` of radare2. The flaw occurs when the function calculates the length for a new buffer allocation using signed integers; specifically, providing a large `stralen` value (e.g., INT_MAX) alongside a replacement string causes a wrapped signed integer calculation. This results in an extremely large or invalid size being passed to `malloc`, leading to an allocation failure or application crash (DoS). The vulnerability requires local access to exploit and has been addressed in commit 11ac224c0eb8d57830fccc99e1c1cd8e5d958813 by implementing checked size arithmetic.
Affected products
- radareorg radare2 up to 6.1.6
Timeline
- 2026-06-04: disclosed: Issue reported on GitHub
- 2026-07-06: advisory: CVE published
- 2026-07-06: patched: Patch identified as commit 11ac224c0eb8d57830fccc99e1c1cd8e5d958813