CVE-2026-14788
published 2026-07-06CVE-2026-14788: A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file…
PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.3th percentile
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The name of the patch is 635ab1eeb30340c26076722a90cb91fb2272130b. Applying a patch is advised to resolve this issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| radare | radare2 | 6.1.0 – 6.1.6 | — |
| radareorg | radare2 | — | — |
| radareorg | radare2 | — | — |
| radareorg | radare2 | — | — |
| radareorg | radare2 | — | — |
| radareorg | radare2 | — | — |
| radareorg | radare2 | — | — |
| radareorg | radare2 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A security vulnerability has been detected in radareorg radare2 up to 6.1.6.
ghsa_unreviewed·2026-07-06
CVE-2026-14788 [LOW] CWE-119 A security vulnerability has been detected in radareorg radare2 up to 6.1.6.
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The name of the patch is 635ab1eeb30340c26076722a90cb91fb2272130b. Applying a patch is advised to resolve this issue.
VulDB
radareorg radare2 up to 6.1.6 libr/core/cfile.c r_core_bin_load use after free (Issue 26049)
vuldb·2026-07-05
CVE-2026-14788 [LOW] radareorg radare2 up to 6.1.6 libr/core/cfile.c r_core_bin_load use after free (Issue 26049)
A vulnerability classified as problematic was found in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free.
This vulnerability is documented as CVE-2026-14788. The attack needs to be performed locally. Additionally, an exploit exists.
Applying a patch is advised to resolve this issue.
Red Hat
radare2: radare2: Denial of Service via use-after-free in r_core_bin_load function
vendor_redhat·2026-07-06·CVSS 3.3
CVE-2026-14788 [LOW] CWE-825 radare2: radare2: Denial of Service via use-after-free in r_core_bin_load function
radare2: radare2: Denial of Service via use-after-free in r_core_bin_load function
A flaw was found in radare2. A local attacker could trigger a use-after-free vulnerability within the r_core_bin_load function. This issue can lead to memory corruption, resulting in a denial of service (DoS) for the application.
Statement: This Low impact flaw in radare2, a reverse engineering framework, allows a local attacker to cause a denial of service. The use-after-free vulnerability in the r_core_bin_load function requires local access and specific interaction with the tool, limiting its broader system impact on typical Red Hat deployments.
Mitigation: To mitigate this issue, ensure that only trusted users have local access to systems where the `radare2` package is installed. If `radare2` is not r
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-14788 radare2: radare2: Denial of Service via use-after-free in r_core_bin_load function
bugzilla·2026-07-06·CVSS 3.3
CVE-2026-14788 [LOW] CVE-2026-14788 radare2: radare2: Denial of Service via use-after-free in r_core_bin_load function
CVE-2026-14788 radare2: radare2: Denial of Service via use-after-free in r_core_bin_load function
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The name of the patch is 635ab1eeb30340c26076722a90cb91fb2272130b. Applying a patch is advised to resolve this issue.
Bugzilla
CVE-2026-14788 radare2: radare2: Denial of Service via use-after-free in r_core_bin_load function [epel-all]
bugzilla·2026-07-06·CVSS 3.3
CVE-2026-14788 [LOW] CVE-2026-14788 radare2: radare2: Denial of Service via use-after-free in r_core_bin_load function [epel-all]
CVE-2026-14788 radare2: radare2: Denial of Service via use-after-free in r_core_bin_load function [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The name of the patch is 635ab1eeb30340c26076722a90cb91fb2272130b. Applying a patch is advised to resolve this issue.
Bugzilla
CVE-2026-14788 radare2: radare2: Denial of Service via use-after-free in r_core_bin_load function [fedora-all]
bugzilla·2026-07-06·CVSS 3.3
CVE-2026-14788 [LOW] CVE-2026-14788 radare2: radare2: Denial of Service via use-after-free in r_core_bin_load function [fedora-all]
CVE-2026-14788 radare2: radare2: Denial of Service via use-after-free in r_core_bin_load function [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The name of the patch is 635ab1eeb30340c26076722a90cb91fb2272130b. Applying a patch is advised to resolve this issue.
2026-07-06
Published