Executive brief
Rizin is an open-source reverse engineering framework used by security researchers to analyze binary files. A memory management flaw in its search functionality could allow a local attacker with physical access to cause the application to crash or behave unexpectedly. This issue is triggered when the tool processes specific search commands with invalid boundaries, potentially disrupting analysis workflows.
Technical details
A double free vulnerability exists in the `byte_pattern_search()` function within `librz/core/cmd/cmd_search.c` of the Rizin framework. The root cause is an incorrect declaration of pointer ownership, leading to the `rz_search_bytes_pattern_free` function being called twice on the same memory address during error handling or specific search operations. Exploitation requires physical access to the machine, high attack complexity, and user interaction. An attacker could potentially cause a denial-of-service (crash) or execute arbitrary code, though the latter is significantly more difficult in this context. The vulnerability has been addressed in commit 045fff363b42b8a6dda8ad5229c29ec3267e7dbe.
Affected products
- rizinorg Rizin dev < 045fff363b42b8a6dda8ad5229c29ec3267e7dbe
Timeline
- 2026-05-11: patched: Fix committed to repository
- 2026-05-12: advisory: GitHub Security Advisory published
- 2026-05-29: disclosed: CVE published in NVD