Impact
An integer overflow occurs within radare2’s cmd_print function, triggered by malformed input to the cmd_print.inc component. The flaw is classified as CWE-189 and CWE-190 and can cause the program to crash or write beyond intended bounds, potentially corrupting memory. The vulnerability is local in nature and does not provide a direct means to elevate privileges or execute code remotely.
Affected Systems
The only affected product is radareorg radare2, versions 6.1.6 and earlier. The vulnerability is present in the cmd_print function across these releases, and no other vendors or products have been reported as affected.
Risk and Exploitability
The CVSS score of 4.8 reflects moderate severity for a local exploit, while the EPSS score of <1% indicates a very low likelihood of current exploitation. The vulnerability is not catalogued in CISA’s KEV. Because the attack vector requires local execution and direct interaction with radare2, the potential impact is limited to program instability and memory corruption rather than broader system compromise.
OpenCVE Enrichment