CVE-2026-14759: radareorg radare2 RBinJava Line Number Table class.c r_bin_java_inner_classes_attr_calc_size heap-based overflow
A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function rbinjavainnerclassesattrcalcsize of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The patch is named cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87. To fix this issue, it is recommended to deploy a patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14759?
The severity of CVE-2026-14759 is classified as low with a score of 3.3.
How do I fix CVE-2026-14759?
To fix CVE-2026-14759, update to radareorg radare2 version 6.1.7 or later, which addresses the heap-based overflow.
What type of vulnerability is CVE-2026-14759?
CVE-2026-14759 is a buffer overflow vulnerability affecting the RBinJava Line Number Table Parser.
What impact does CVE-2026-14759 have on the system?
CVE-2026-14759 can lead to heap-based buffer overflow, which might allow attackers to execute arbitrary code.
Is CVE-2026-14759 exploitable remotely?
CVE-2026-14759 has a low attack vector score, suggesting it is not easily exploitable remotely.