Impact
A local integer overflow flaw exists in the core_anal_bytes function of radare2. Manipulating certain input data during analysis can cause an integer overflow, resulting in memory corruption adjacent to the affected buffer and potentially causing a crash. The vulnerability is identified by CWE-189 and CWE-190, indicating improper handling of signed and unsigned integer values.
Affected Systems
The affected product is radareorg radare2, with all releases up to and including version 6.1.6 vulnerable. Users who have not applied the available fix are at risk.
Risk and Exploitability
The CVSS score of 4.8 reflects moderate severity, and the EPSS score of < 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local execution, so the impact is confined to the host machine where radare2 is run. No widespread exploitation has been reported, but the potential for local memory corruption warrants remediation.
OpenCVE Enrichment