CVE-2025-1378
A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286.
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function in the library /libr/main/rasm2.c of the component rasm2. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0.0 is able to address this issue. The patch is identified as c6c772d2eab692ce7ada5a4227afd50c355ad545. It is recommended to upgrade the affected component.
- CVSS 4.0
- 4.8 MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.32% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- radare/radare2
- Source
- cna@vuldb.com
References
- https://github.com/radareorg/radare2/commit/c6c772d2eab692ce7ada5a4227afd50c355ad545Patch
- https://github.com/radareorg/radare2/issues/23953Exploit, Issue Tracking, Vendor Advisory
- https://github.com/radareorg/radare2/issues/23953#issue-2844325926Exploit, Issue Tracking, Vendor Advisory
- https://github.com/radareorg/radare2/milestone/86Release Notes
- https://vuldb.com/?ctiid.295986Permissions Required, VDB Entry
- https://vuldb.com/?id.295986Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.498499Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.