Impact
A double‑free bug exists in the LE binary loader. When a malformed or circular LE fixup chain is processed, the loader attempts to free already freed relocation entries during error handling, corrupting the heap and causing the application to crash. An attacker who can supply a malicious LE file can trigger this overflow and result in a loss of service.
Affected Systems
Any installation of the Rizin binary analysis suite that processes LE binaries is affected, as the flaw resides in the librz/format/le component. Users running the tool in data‑processing pipelines or services that accept arbitrary LE files should consider their environments vulnerable.
Risk and Exploitability
The vulnerability has a high impact because it results in a complete denial of service. No CVSS score is supplied and the EPSS score is unavailable, but the flaw is not listed in the KEV catalog. The likely attack vector is the delivery of a crafted LE file, which can occur locally or over a network if the Rizin instance is exposed.
OpenCVE Enrichment