CVE-2026-14760 PUBLISHED

radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free

Assigner: VulDB
Reserved: 04.07.2026 Published: 05.07.2026 Updated: 05.07.2026

A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 4.8

Product Status

Vendor radareorg
Product radare2
Versions
  • Version 6.1.0 is affected
  • Version 6.1.1 is affected
  • Version 6.1.2 is affected
  • Version 6.1.3 is affected
  • Version 6.1.4 is affected
  • Version 6.1.5 is affected
  • Version 6.1.6 is affected

Credits

  • Kery Qi (VulDB User) reporter

References

Problem Types

  • Use After Free CWE
  • Memory Corruption CWE