CVE-2021-4021: High severity radare2 vulnerability
Published Feb 24, 2022
·Updated
A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and DoS.
Affected Software
1 affected component
Radare Radare2<=5.5.0
Event History
Feb 24, 2022
CVE Published
via MITRE·06:50 PM
Data Sourced
via MITRE·06:50 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Radare2 vulnerability?
The vulnerability ID for this Radare2 vulnerability is CVE-2021-4021.
2
What is the severity of CVE-2021-4021?
The severity of CVE-2021-4021 is high with a CVSS score of 7.5.
3
Which versions of Radare2 are affected by CVE-2021-4021?
Versions of Radare2 prior to 5.6.2, 5.6.0, 5.5.4, and 5.5.2 are affected by CVE-2021-4021.
4
What is the impact of CVE-2021-4021?
CVE-2021-4021 can lead to uncontrolled resource consumption and DoS (Denial of Service).
5
Is there a fix available for CVE-2021-4021?
Yes, upgrading to Radare2 version 5.6.2 or later can fix CVE-2021-4021.