PT-2026-41375 · Radare2 · Radare2

Saad Elharaj

·

Published

2026-05-15

·

Updated

2026-05-15

·

CVE-2026-8696

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
radare2 6.1.5 contains a use-after-free vulnerability in the gdbr pids list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed thread information responses. Attackers can trigger the vulnerability by causing qsThreadInfo to fail after qfThreadInfo successfully allocates RDebugPid structures, resulting in double-free memory corruption when the error path attempts to clean up the list.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2026-8696

Affected Products

Radare2