SEPTEMBER 30, 2026
Live Feed
Back to database
Case File

CVE-2026-81883

LOW · CVSS 3.3 EPSS 0.16% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-09-30

CyberRota Analysis

AI-Generated

The Lua 5.3 bytecode function parser in radare2 versions prior to 6.2.0 is vulnerable due to improper buffer length checks, allowing it to read beyond the allocated input buffer when processing crafted Lua files. This can lead to invalid parser results or process termination, although no memory disclosure has been observed. Users of radare2, especially those handling Lua bytecode, should prioritize upgrading to version 6.2.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81883
Severity
LOW
CVSS
3.3
EPSS
0.16%

Original NVD Description

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecode function parser was vulnerable because the Lua 5.3 bytecode function parser read fixed function-metadata fields immediately after a function-name string without checking the remaining buffer length. The vulnerability is triggered by opening or inspecting a crafted Lua 5.3 bytecode file whose function-name string ends at the input-buffer boundary. The parser read two integers and three one-byte fields beyond the allocated input buffer. This can cause invalid parser results or process termination; no attacker-observable memory disclosure has been demonstrated. This issue is fixed in version 6.2.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)