CVE-2026-14760
A weakness has been identified in radareorg radare2 up to 6.1.6.
Does this matter?
Lower severity and a low EPSS score (0.20%). Track it; it rarely justifies an emergency change on its own.
Description
A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.
- CVSS 4.0
- 1.9 LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.20% probability · 10th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-416
- Affected
- radare/radare2
- Source
- cna@vuldb.com
References
- https://github.com/radareorg/radare2/Product
- https://github.com/radareorg/radare2/commit/8b25c773785d85cb0103410a0905089d286921c2Patch
- https://github.com/radareorg/radare2/issues/26044Exploit, Issue Tracking
- https://vuldb.com/cve/CVE-2026-14760Third Party Advisory, VDB Entry
- https://vuldb.com/submit/850384Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/376349Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/376349/ctiPermissions Required, VDB Entry
- https://vuldb.com/submit/850384Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.