Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
1.9

CVE-2026-14757: radare2 Integer Overflow Allows Local Privilege Escalation

CVE-2026-14757 CVE-2026-14757
Summary

A vulnerability in radare2 versions up to 6.1.6 allows an attacker to gain elevated privileges on a local system. This is a serious issue because it could be exploited by an attacker who has access to the system. To protect yourself, you should update to the latest version of radare2 or apply the recommended patch.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
radareorg radare2 6.1.0
radare radare2 >= 6.1.0, < 6.1.8
cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:*
Original title
A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack ...
Original description
A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. It is suggested to install a patch to address this issue.
nvd CVSS2.0 4.3
nvd CVSS3.1 5.3
nvd CVSS4.0 1.9
Vulnerability type
CWE-189
CWE-190 Integer Overflow
Published: 5 Jul 2026 · Updated: 8 Jul 2026 · First seen: 5 Jul 2026