cbcvebase.
CVE-2021-32495
published 2023-07-07

CVE-2021-32495: Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afterwards. This will allow attackers to…

PriorityP339critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.76%
51.2th percentile
Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afterwards. This will allow attackers to cause denial of service.

Affected

3 ranges
VendorProductVersion rangeFixed in
debianradare2< radare2 5.5.0+dfsg-1 (sid)radare2 5.5.0+dfsg-1 (sid)
radareradare2
radare2radare2

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.1CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.