First published: Mon Apr 11 2022(Updated: )
Out-of-bounds read in `r_bin_ne_get_relocs` function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Radare Radare2 | <5.6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1296 is an out-of-bounds read vulnerability in the r_bin_ne_get_relocs function in the radareorg/radare2 GitHub repository prior to version 5.6.8.
CVE-2022-1296 may allow attackers to read sensitive information or cause a crash.
The severity of CVE-2022-1296 is rated as critical with a CVSS score of 9.1.
To fix CVE-2022-1296, it is recommended to update the radareorg/radare2 software to version 5.6.8 or later.
More information about CVE-2022-1296 can be found at the following references: [GitHub Commit](https://github.com/radareorg/radare2/commit/153bcdc29f11cd8c90e7d639a7405450f644ddb6) and [Huntr Bounties](https://huntr.dev/bounties/52b57274-0e1a-4d61-ab29-1373b555fea0).