CVE-2021-32613: Use After Free
Published May 12, 2021
·Updated
In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.
Affected Software
3 affected components
Radare Radare2<=5.3.0
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
May 12, 2021
Data Sourced
via Red Hat·05:06 PM
DescriptionSeverityAffected Software
May 14, 2021
CVE Published
via MITRE·12:11 PM
Data Sourced
via MITRE·12:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-32613?
CVE-2021-32613 is classified as a medium severity vulnerability due to its potential for denial of service (DoS).
2
How do I fix CVE-2021-32613?
To fix CVE-2021-32613, upgrade radare2 to version 5.4.0 or later where the vulnerability is patched.
3
What causes the vulnerability in CVE-2021-32613?
The vulnerability in CVE-2021-32613 is caused by a double free in the pyc parser when handling specially crafted files.
4
Which versions of radare2 are affected by CVE-2021-32613?
CVE-2021-32613 affects radare2 versions up to and including 5.3.0.
5
Can CVE-2021-32613 lead to data loss?
CVE-2021-32613 specifically can lead to a denial of service (DoS) but does not directly cause data loss.