Debian Radare2 vulnerabilities
146 known vulnerabilities affecting debian/radare2.
Total CVEs
146
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH51MEDIUM41LOW40
Vulnerabilities
Page 7 of 8
CVE-2022-34520P4MEDIUMCVSS 5.5fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-34520 [MEDIUM] CVE-2022-34520: radare2 - Radare2 v5.7.2 was discovered to contain a NULL pointer dereference via the func...
Radare2 v5.7.2 was discovered to contain a NULL pointer dereference via the function r_bin_file_xtr_load_buffer at bin/bfile.c. This vulnerability allows attackers to cause a Denial of Service (DOS) via a crafted binary file.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2024-26475P4MEDIUMCVSS 5.5fixed in radare2 5.9.0+dfsg-1 (sid)2024
CVE-2024-26475 [MEDIUM] CVE-2024-26475: radare2 - An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allow...
An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent function.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2024-48241P4MEDIUMCVSS 5.5fixed in radare2 5.9.8+dfsg-1 (sid)2024
CVE-2024-48241 [MEDIUM] CVE-2024-48241: radare2 - An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a den...
An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.
Scope: local
sid: resolved (fixed in 5.9.8+dfsg-1)
debian
CVE-2025-60358P4MEDIUMCVSS 5.5fixed in radare2 6.0.4+dfsg-1 (sid)2025
CVE-2025-60358 [MEDIUM] CVE-2025-60358: radare2 - radare2 v.5.9.8 and before contains a memory leak in the function _load_relocati...
radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.
Scope: local
sid: resolved (fixed in 6.0.4+dfsg-1)
debian
CVE-2017-9520P4LOWCVSS 5.5fixed in radare2 1.6.0+dfsg-1 (sid)2017
CVE-2017-9520 [MEDIUM] CVE-2017-9520: radare2 - The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote...
The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted DEX file.
Scope: local
sid: resolved (fixed in 1.6.0+dfsg-1)
debian
CVE-2022-0476P4MEDIUMCVSS 5.5fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-0476 [MEDIUM] CVE-2022-0476: radare2 - Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2017-9762P4LOWCVSS 5.5fixed in radare2 1.6.0+dfsg-1 (sid)2017
CVE-2017-9762 [MEDIUM] CVE-2017-9762: radare2 - The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote att...
The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted binary file.
Scope: local
sid: resolved (fixed in 1.6.0+dfsg-1)
debian
CVE-2022-0695P4MEDIUMCVSS 5.5fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-0695 [MEDIUM] CVE-2022-0695: radare2 - Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2018-11380P4LOWCVSS 5.5fixed in radare2 2.6.0+dfsg-1 (sid)2018
CVE-2018-11380 [MEDIUM] CVE-2018-11380: radare2 - The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to caus...
The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted Mach-O file.
Scope: local
sid: resolved (fixed in 2.6.0+dfsg-1)
debian
CVE-2018-11381P4LOWCVSS 5.5fixed in radare2 2.6.0+dfsg-1 (sid)2018
CVE-2018-11381 [MEDIUM] CVE-2018-11381: radare2 - The string_scan_range() function in radare2 2.5.0 allows remote attackers to cau...
The string_scan_range() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
Scope: local
sid: resolved (fixed in 2.6.0+dfsg-1)
debian
CVE-2017-7946P4LOWCVSS 5.5fixed in radare2 1.1.0+dfsg-5 (sid)2017
CVE-2017-7946 [MEDIUM] CVE-2017-7946: radare2 - The get_relocs_64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 all...
The get_relocs_64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted Mach0 file.
Scope: local
sid: resolved (fixed in 1.1.0+dfsg-5)
debian
CVE-2017-16805P4MEDIUMCVSS 5.5fixed in radare2 2.1.0+dfsg-1 (sid)2017
CVE-2017-16805 [MEDIUM] CVE-2017-16805: radare2 - In radare2 2.0.1, libr/bin/dwarf.c allows remote attackers to cause a denial of ...
In radare2 2.0.1, libr/bin/dwarf.c allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file, related to r_bin_dwarf_parse_comp_unit in dwarf.c and sdb_set_internal in shlr/sdb/src/sdb.c.
Scope: local
sid: resolved (fixed in 2.1.0+dfsg-1)
debian
CVE-2018-20461P4LOWCVSS 5.5fixed in radare2 3.1.2+dfsg-1 (sid)2018
CVE-2018-20461 [MEDIUM] CVE-2018-20461: radare2 - In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attack...
In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting a binary file.
Scope: local
sid: resolved (fixed in 3.1.2+dfsg-1)
debian
CVE-2018-20458P4LOWCVSS 5.5fixed in radare2 3.1.2+dfsg-1 (sid)2018
CVE-2018-20458 [MEDIUM] CVE-2018-20458: radare2 - In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyld...
In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting an input file.
Scope: local
sid: resolved (fixed in 3.1.2+dfsg-1)
debian
CVE-2022-1283P4MEDIUMCVSS 5.5fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1283 [MEDIUM] CVE-2022-1283: radare2 - NULL Pointer Dereference in r_bin_ne_get_entrypoints function in GitHub reposito...
NULL Pointer Dereference in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to cause a denial of service (application crash).
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2025-1378P4MEDIUMCVSS 4.8fixed in radare2 6.0.4+dfsg-1 (sid)2025
CVE-2025-1378 [MEDIUM] CVE-2025-1378: radare2 - A vulnerability, which was classified as problematic, was found in radare2 5.9.9...
A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function in the library /libr/main/rasm2.c of the component rasm2. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0.0 is able to addre
debian
CVE-2025-5648P4LOWCVSS 2.0fixed in radare2 6.0.4+dfsg-1 (sid)2025
CVE-2025-5648 [LOW] CVE-2025-5648: radare2 - A vulnerability was found in Radare2 5.9.9. It has been classified as problemati...
A vulnerability was found in Radare2 5.9.9. It has been classified as problematic. Affected is the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. An attack has to be approached locally. The complexity of an attack is rather high. The exploitability is told to be difficul
debian
CVE-2025-5642P4LOWCVSS 2.0fixed in radare2 6.0.4+dfsg-1 (sid)2025
CVE-2025-5642 [LOW] CVE-2025-5642: radare2 - A vulnerability classified as problematic has been found in Radare2 5.9.9. Affec...
A vulnerability classified as problematic has been found in Radare2 5.9.9. Affected is the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The manipulation leads to memory corruption. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been
debian
CVE-2025-5643P4LOWCVSS 2.0fixed in radare2 6.0.4+dfsg-1 (sid)2025
CVE-2025-5643 [LOW] CVE-2025-5643: radare2 - A vulnerability classified as problematic was found in Radare2 5.9.9. Affected b...
A vulnerability classified as problematic was found in Radare2 5.9.9. Affected by this vulnerability is the function cons_stack_load in the library /libr/cons/cons.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation appears to be
debian
CVE-2025-5644P4LOWCVSS 2.0fixed in radare2 6.0.4+dfsg-1 (sid)2025
CVE-2025-5644 [LOW] CVE-2025-5644: radare2 - A vulnerability, which was classified as problematic, has been found in Radare2 ...
A vulnerability, which was classified as problematic, has been found in Radare2 5.9.9. Affected by this issue is the function r_cons_flush in the library /libr/cons/cons.c of the component radiff2. The manipulation of the argument -T leads to use after free. Local access is required to approach this attack. The complexity of an attack is rather high. The exploitation i
debian