PT-2026-96776 · Radare2 · Radare2

CVE-2026-81880

·

Published

2026-09-22

·

Updated

2026-09-25

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions radare2 versions prior to 6.2.0
Description The Apple Preferred Executable Format (PEF) loader fails to properly bound relocSecCount values against the number of sections or complete relocation records in the input. This issue is triggered during the automatic binary-format detection of a specially crafted Apple PEF file. Consequently, the loader may perform up to 268,435,456 relocation-section iterations and repeated buffer operations after record offsets exceed the end of the file, leading to a denial of service due to excessive CPU consumption and prolonged processing.
Recommendations Update to version 6.2.0.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81880
GHSA-FG6F-RJ8G-25PQ

Affected Products

Radare2