CVE-2024-26475: Null Pointer Dereference
Published Mar 14, 2024
·Updated
An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grubsfsreadextent function.
Affected Software
2 affected components
radareorg radare2>=0.9.7<=5.8.6
Radare Radare2>=0.9.7<5.8.8
Remediation
Patch Available
Event History
Mar 14, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-26475?
CVE-2024-26475 is classified as a denial of service vulnerability.
2
How do I fix CVE-2024-26475?
To fix CVE-2024-26475, upgrade radare2 to version 5.8.8 or later.
3
Who is affected by CVE-2024-26475?
CVE-2024-26475 affects local users of radare2 versions 0.9.7 to 5.8.6.
4
What is the impact of CVE-2024-26475?
The impact of CVE-2024-26475 is a denial of service that can disrupt the functioning of the application.
5
Is CVE-2024-26475 a remote exploit?
No, CVE-2024-26475 is a local exploit requiring access to the system.