PT-2026-96777 · Radare2 · Radare2
CVE-2026-81881
·
Published
2026-09-22
·
Updated
2026-09-25
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
radare2 versions prior to 6.2.0
Description
The Mach-O Swift field-metadata parser contains a flaw where a relative Swift field pointer can be lower than the field-metadata section base. This causes subtraction to produce a negative logical index when parsing Swift type and class metadata from a specially crafted Mach-O file. The resulting index is used to read four bytes immediately before the allocated field-metadata buffer, which may lead to incorrect metadata processing or process termination.
Recommendations
Update to version 6.2.0.
Exploit
Fix
Integer Underflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Radare2