CVE-2021-32495
published 2023-07-07CVE-2021-32495: Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afterwards. This will allow attackers to…
PriorityP339critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.76%
51.2th percentile
Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afterwards. This will allow attackers to cause denial of service.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | radare2 | < radare2 5.5.0+dfsg-1 (sid) | radare2 5.5.0+dfsg-1 (sid) |
| radare | radare2 | — | — |
| radare2 | radare2 | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.1CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2021-32495: radare2 - Radare2 has a use-after-free vulnerability in pyc parser's get_none_object funct...
vendor_debian·2021·CVSS 10.0
CVE-2021-32495 [CRITICAL] CVE-2021-32495: radare2 - Radare2 has a use-after-free vulnerability in pyc parser's get_none_object funct...
Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afterwards. This will allow attackers to cause denial of service.
Scope: local
sid: resolved (fixed in 5.5.0+dfsg-1)
GHSA
GHSA-43pp-rgp9-c5h8: Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function
ghsa_unreviewed·2023-07-07
CVE-2021-32495 [CRITICAL] CWE-416 GHSA-43pp-rgp9-c5h8: Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function
Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afterwards. This will allow attackers to cause denial of service.
OSV
CVE-2021-32495: Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function
osv·2023-07-07·CVSS 9.1
CVE-2021-32495 [CRITICAL] CVE-2021-32495: Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function
Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afterwards. This will allow attackers to cause denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-07
Published