PT-2026-55811 · Radareorg · Radare2

Kery Qi

·

Published

2026-07-05

·

Updated

2026-07-05

·

CVE-2026-14761

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is the function r str ndup/r str append of the file libr/util/str.c. The manipulation leads to integer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The identifier of the patch is a20a56917ae85d732e683f8d9078bdcfee92446c. Applying a patch is the recommended action to fix this issue.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14761

Affected Products

Radare2