PT-2026-96777 · Radare2 · Radare2

CVE-2026-81881

·

Published

2026-09-22

·

Updated

2026-09-25

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions radare2 versions prior to 6.2.0
Description The Mach-O Swift field-metadata parser contains a flaw where a relative Swift field pointer can be lower than the field-metadata section base. This causes subtraction to produce a negative logical index when parsing Swift type and class metadata from a specially crafted Mach-O file. The resulting index is used to read four bytes immediately before the allocated field-metadata buffer, which may lead to incorrect metadata processing or process termination.
Recommendations Update to version 6.2.0.

Exploit

Fix

Integer Underflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81881
GHSA-Q4W7-225G-64J9

Affected Products

Radare2