CVE-2026-14761: radareorg radare2 str.c r_str_append integer overflow
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is the function rstrndup/rstrappend of the file libr/util/str.c. The manipulation leads to integer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The identifier of the patch is a20a56917ae85d732e683f8d9078bdcfee92446c. Applying a patch is the recommended action to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
radareorg/radare2to a version that resolves this vulnerability.Patch a20a56917ae85d732e683f8d9078bdcfee92446c
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14761?
The severity of CVE-2026-14761 is low, with a score of 3.3.
What software is affected by CVE-2026-14761?
CVE-2026-14761 affects radareorg radare2 versions up to 6.1.6.
What type of vulnerability is CVE-2026-14761?
CVE-2026-14761 is classified as an integer overflow vulnerability.
How do I fix CVE-2026-14761?
To fix CVE-2026-14761, upgrade radareorg radare2 to the latest version that addresses this vulnerability.
What is the impact of CVE-2026-14761?
The impact of CVE-2026-14761 allows for integer overflow which could potentially lead to local exploitation.