Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Radareorg
Radareorg radare2 |
|
| Vendors & Products |
Radareorg
Radareorg radare2 |
Tue, 22 Sep 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted dataoff and datasize and allowed a final partial record to be processed. The vulnerability is triggered by opening a crafted Mach-O file while the non-default bin.verbose option is enabled. When datasize was not a multiple of data_in_code_entry, the last iteration read beyond the allocated buffer. This can cause a heap out-of-bounds read and possible process termination; no attacker-observable memory disclosure has been demonstrated. This issue is fixed in version 6.2.0. | |
| Title | radare2: Heap out-of-bounds read in radare2 Mach-O LC_DATA_IN_CODE parser | |
| Weaknesses | CWE-125 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-22T15:40:10.955Z
Reserved: 2026-08-27T17:48:42.122Z
Link: CVE-2026-81884
No data.
Status : Received
Published: 2026-09-22T16:18:03.347
Modified: 2026-09-22T16:18:03.347
Link: CVE-2026-81884
No data.
OpenCVE Enrichment
Updated: 2026-09-22T17:00:11Z