Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
1.9

CVE-2026-14760: radare2: Local Attack Possible Through Code Execution

CVE-2026-14760
Summary

A vulnerability in radare2 version 6.1.6 and earlier allows an attacker with local access to potentially execute malicious code. This could lead to unauthorized actions on a system. We recommend updating to the latest version to address this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
radare radare2 < 6.1.8
cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:*
Original title
A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manip...
Original description
A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.
nvd CVSS2.0 1.7
nvd CVSS3.1 3.3
nvd CVSS4.0 1.9
Vulnerability type
CWE-119 Buffer Overflow
CWE-416 Use After Free
Published: 5 Jul 2026 · Updated: 8 Jul 2026 · First seen: 5 Jul 2026