Impact
The flaw exists in radare2’s r_core_bin_load function in libr/core/cfile.c, where an improperly handled memory free can be triggered by local input. When exploited, this use‑after‑free corrupts memory, which may cause a crash or allow an attacker with sufficient privileges to inject further manipulation. The vulnerability is linked to the identified weaknesses of CWE‑416, CWE‑119, and CWE‑825. It is a local issue, requiring the attacker to be able to supply data to the vulnerable function.
Affected Systems
radareorg’s radare2, all releases up to and including version 6.1.6, remain vulnerable until the patch commit 635ab1eeb30340c26076722a90cb91fb2272130b is applied.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate risk, while the EPSS score of less than 1% suggests a very low probability that this vulnerability will be actively exploited. The vulnerability is not listed in the CISA KEV catalog, and exploitation requires local access to the radare2 installation.
OpenCVE Enrichment