SEPTEMBER 30, 2026
Live Feed
Back to database
Case File

CVE-2026-81884

LOW · CVSS 2.5 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-09-30

CyberRota Analysis

AI-Generated

The Mach-O LC_DATA_IN_CODE parser in radare2 versions prior to 6.2.0 is vulnerable to a heap out-of-bounds read when processing specially crafted Mach-O files with the non-default bin.verbose option enabled. This can lead to potential process termination, although no memory disclosure has been observed. Users of radare2, particularly those working with Mach-O files, should prioritize upgrading to version 6.2.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81884
Severity
LOW
CVSS
2.5
EPSS
0.15%

Original NVD Description

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted dataoff and datasize and allowed a final partial record to be processed. The vulnerability is triggered by opening a crafted Mach-O file while the non-default bin.verbose option is enabled. When datasize was not a multiple of data_in_code_entry, the last iteration read beyond the allocated buffer. This can cause a heap out-of-bounds read and possible process termination; no attacker-observable memory disclosure has been demonstrated. This issue is fixed in version 6.2.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)