Junglewise Threat Intelligence

CVE-2026-81886: radare2 unbounded allocation in dmp64 parser

CVE-2026-81886 · Severity: medium · CVSS 5.5 · Published 2026-09-22

Executive brief

radare2 is a reverse engineering framework used to analyze binary files and crash dumps. A flaw in its Windows 64-bit crash dump parser allows an attacker to craft a malicious dump file that triggers uncontrolled memory allocation when opened, causing the tool to hang or crash—denying analysts access to the system for forensic investigation.

Technical details

The dmp64 parser in radare2 prior to 6.2.0 reads a page count directly from an untrusted crash dump file and uses it as a loop bound for heap allocation without validating it against the dump file size. An attacker can craft a DMP file with the magic "PAGEDU64", DumpType=1, and a PageCount field set to 0xFFFFFFFFFFFFFFFF to trigger unbounded allocation. The vulnerability is reached on file open and requires no user interaction beyond opening the malicious file.

Affected products

  • radareorg radare2 before 6.2.0

Timeline

  • 2026-07-12: disclosed
  • 2026-07-06: patched: commit a7519fdb4da6835c2cecd8fe248e7dd1133cf17a
  • 2026-09-22: advisory

References

Related threats