PT-2026-96775 · Radare2 · Radare2

CVE-2026-81879

·

Published

2026-09-22

·

Updated

2026-09-25

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions radare2 versions prior to 6.2.0
Description The ELF parser in radare2 incorrectly handles PN XNUM, which is a special value used in ELF files to indicate that the number of program headers is stored elsewhere. The software allocates the program-header array based on the resolved PN XNUM count, but some components continue to iterate using the original e phnum value of 65535. When processing a specially crafted ELF file where e phnum is set to 0xffff and the resolved count in shdr[0].sh info is significantly smaller, the system iterates beyond the allocated memory. This leads to a heap out-of-bounds read, which can cause process termination and a denial of service.
Recommendations Update to version 6.2.0.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81879
GHSA-JQFQ-HVCP-XH4P

Affected Products

Radare2