PT-2026-96775 · Radare2 · Radare2
CVE-2026-81879
·
Published
2026-09-22
·
Updated
2026-09-25
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
radare2 versions prior to 6.2.0
Description
The ELF parser in radare2 incorrectly handles PN XNUM, which is a special value used in ELF files to indicate that the number of program headers is stored elsewhere. The software allocates the program-header array based on the resolved PN XNUM count, but some components continue to iterate using the original
e phnum value of 65535. When processing a specially crafted ELF file where e phnum is set to 0xffff and the resolved count in shdr[0].sh info is significantly smaller, the system iterates beyond the allocated memory. This leads to a heap out-of-bounds read, which can cause process termination and a denial of service.Recommendations
Update to version 6.2.0.
Exploit
Fix
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Radare2