Impact
A local integer overflow flaw exists in radare2’s cmd_print function within the cmd_print.inc component, allowing malformed input to that can lead to program crashes or unintended memory corruption. The weakness is categorized as CWE-189 and CWE-190 and does not provide privilege escalation or remote code execution capabilities.
Affected Systems
The affected product is radareorg radare2 version 6.1.6 and earlier. The official patch commit 2b6265476c75567006b0fcbb749f4ae7b189c5df issue. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity for a local exploit. The EPSS score of < 1% shows a very low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local execution or direct interaction with radare2, and although a public vector is described. Consequently, the potential impact is limited to program crashes or memory corruption rather than escalation or remote compromise.
OpenCVE Enrichment