CVE-2025-63745: Null Pointer Dereference
A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of binne.c. A crafted binary input can trigger a segmentation fault, leading to a denial of service when the tool processes malformed data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63745?
CVE-2025-63745 has a severity rating that indicates it can lead to a denial of service due to a NULL pointer dereference.
How do I fix CVE-2025-63745?
To fix CVE-2025-63745, upgrade radare2 to version 6.0.6 or later where the vulnerability is addressed.
What versions of radare2 are affected by CVE-2025-63745?
CVE-2025-63745 affects radare2 version 6.0.5 and earlier.
What happens if I exploit CVE-2025-63745?
Exploiting CVE-2025-63745 can trigger a segmentation fault, causing a denial of service for users processing malformed binaries.
Is CVE-2025-63745 a remote or local vulnerability?
CVE-2025-63745 can be exploited locally by providing crafted binary input to the affected version of radare2.