Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-84040
HistoryMar 24, 2022 - 12:00 a.m.

Radare2 post-release reuse vulnerability

2022-03-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
radare2
post-release
reuse vulnerability
version 5.6.6
op_is_set_bp directive
memory confusion
program crashes
arbitrary code execution
security

EPSS

0.001

Percentile

31.9%

Radare2 is a set of libraries and tools for working with binaries. a post-release reuse vulnerability exists in versions of Radare2 prior to 5.6.6, which stems from a confusion in the op_is_set_bp directive responsible for freeing memory in radare2 5.6.6. An attacker could exploit this vulnerability to cause program crashes, arbitrary code execution, etc.