Executive brief
radare2 is a popular open-source framework for reverse engineering and analyzing binary files. A vulnerability in its memory dump (MDMP) file parser could allow a local attacker to cause a crash or potentially execute unauthorized code by providing a specially crafted, truncated file. This could disrupt security analysis workflows or be used as part of a multi-stage attack on a researcher's workstation.
Technical details
A stack-based buffer overflow and out-of-bounds read vulnerability exists in radare2 up to version 6.1.6 within the Memory64ListStream parser located in libr/bin/format/mdmp/mdmp.c. The root cause is a failure to validate that the declared DataSize of a stream is sufficient to contain the descriptor array (MINIDUMP_MEMORY_DESCRIPTOR64). An attacker can provide a truncated MDMP file where the NumberOfMemoryRanges indicates more descriptors than the stream size allows, causing the parser to read past the declared stream boundary. This can lead to a crash (DoS) or potentially further memory corruption. A patch has been developed (commit 175d4addb68981331c85b10681c2161c38fb5762) to enforce proper bounds checking.
Affected products
- radareorg radare2 up to 6.1.6
Timeline
- 2026-06-05: disclosed: Issue reported on GitHub repository
- 2026-07-06: advisory: NVD publication date
References
- https://github.com/mengzhisuoliu/radare2/commit/175d4addb68981331c85b10681c2161c38fb5762
- https://github.com/radareorg/radare2/
- https://github.com/radareorg/radare2/issues/26051
- https://vuldb.com/cve/CVE-2026-14789
- https://vuldb.com/submit/850389
- https://vuldb.com/vuln/376378
- https://vuldb.com/vuln/376378/cti