CVE-2026-14757

Name
CVE-2026-14757
Description
A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. It is suggested to install a patch to address this issue.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cna@vuldb.com https://github.com/radareorg/radare2/
cna@vuldb.com https://github.com/radareorg/radare2/issues/26041
cna@vuldb.com https://vuldb.com/cve/CVE-2026-14757
cna@vuldb.com https://vuldb.com/submit/850381
cna@vuldb.com https://vuldb.com/vuln/376346
cna@vuldb.com https://vuldb.com/vuln/376346/cti

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:* radare2 >= 6.1.0 < 6.1.8

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
radare2 edge-community 6.1.6-r0 omni <omni+alpine@hack.org> possibly vulnerable
radare2 edge-community 6.1.4-r0 omni <omni+alpine@hack.org> possibly vulnerable
radare2 edge-community 6.1.2-r0 omni <omni+alpine@hack.org> possibly vulnerable
radare2 3.24-community 6.1.6-r0 omni <omni+alpine@hack.org> possibly vulnerable