CVE-2026-14760
published 2026-07-05CVE-2026-14760: A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.3th percentile
A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| radare | radare2 | >= 6.1.0 < 6.1.8 | 6.1.8 |
| radareorg | radare2 | — | — |
| radareorg | radare2 | — | — |
| radareorg | radare2 | — | — |
| radareorg | radare2 | — | — |
| radareorg | radare2 | — | — |
| radareorg | radare2 | — | — |
| radareorg | radare2 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A weakness has been identified in radareorg radare2 up to 6.1.6.
ghsa_unreviewed·2026-07-05
CVE-2026-14760 [LOW] CWE-119 A weakness has been identified in radareorg radare2 up to 6.1.6.
A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.
VulDB
radareorg radare2 up to 6.1.6 regprofile libr/core/disasm.c r_core_seek_arch_bits use after free (Issue 26044)
vuldb·2026-07-04
CVE-2026-14760 [LOW] radareorg radare2 up to 6.1.6 regprofile libr/core/disasm.c r_core_seek_arch_bits use after free (Issue 26044)
A vulnerability classified as problematic was found in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free.
This vulnerability appears as CVE-2026-14760. The attack requires local access. In addition, an exploit is available.
It is advisable to implement a patch to correct this issue.
Red Hat
radare2: radare2: Denial of Service via local use-after-free vulnerability
vendor_redhat·2026-07-05·CVSS 3.3
CVE-2026-14760 [LOW] CWE-825 radare2: radare2: Denial of Service via local use-after-free vulnerability
radare2: radare2: Denial of Service via local use-after-free vulnerability
A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.
A flaw was found in radareorg radare2. This vulnerability, a use-after-free, affects the `regprofile Handler` component. A local attacker can exploit this flaw by performing a specific manipulation, which could lead to a denial of service, making the a
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-14760 radare2: radare2: Denial of Service via local use-after-free vulnerability [fedora-all]
bugzilla·2026-07-06·CVSS 3.3
CVE-2026-14760 [LOW] CVE-2026-14760 radare2: radare2: Denial of Service via local use-after-free vulnerability [fedora-all]
CVE-2026-14760 radare2: radare2: Denial of Service via local use-after-free vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.
Bugzilla
CVE-2026-14760 radare2: radare2: Denial of Service via local use-after-free vulnerability [epel-all]
bugzilla·2026-07-06·CVSS 3.3
CVE-2026-14760 [LOW] CVE-2026-14760 radare2: radare2: Denial of Service via local use-after-free vulnerability [epel-all]
CVE-2026-14760 radare2: radare2: Denial of Service via local use-after-free vulnerability [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.
Bugzilla
CVE-2026-14760 radare2: radare2: Denial of Service via local use-after-free vulnerability
bugzilla·2026-07-05·CVSS 3.3
CVE-2026-14760 [LOW] CVE-2026-14760 radare2: radare2: Denial of Service via local use-after-free vulnerability
CVE-2026-14760 radare2: radare2: Denial of Service via local use-after-free vulnerability
A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.
https://github.com/radareorg/radare2/https://github.com/radareorg/radare2/commit/8b25c773785d85cb0103410a0905089d286921c2https://github.com/radareorg/radare2/issues/26044https://vuldb.com/cve/CVE-2026-14760https://vuldb.com/submit/850384https://vuldb.com/vuln/376349https://vuldb.com/vuln/376349/ctihttps://vuldb.com/submit/850384
2026-07-05
Published