CVE-2026-14787: radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow
A weakness has been identified in radareorg radare2 up to 6.1.6. Affected is the function cmdprint in the library libr/core/cmdprint.inc of the component pb Print Command Handler. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch name: 2b6265476c75567006b0fcbb749f4ae7b189c5df. It is recommended to apply a patch to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
radareorg radare2to a version that resolves this vulnerability.Patch 2b6265476c75567006b0fcbb749f4ae7b189c5df
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14787?
CVE-2026-14787 has a severity rating of low at 3.3.
What type of vulnerability is CVE-2026-14787?
CVE-2026-14787 is categorized as an integer overflow vulnerability.
How do I fix CVE-2026-14787?
To mitigate CVE-2026-14787, update radareorg radare2 to version 6.1.7 or later.
Who is affected by CVE-2026-14787?
CVE-2026-14787 affects users of radareorg radare2 versions up to 6.1.6.
What attack vector is used for CVE-2026-14787?
CVE-2026-14787 requires local access to exploit the integer overflow vulnerability.