CVE-2026-81878: radare2: Integer overflow causes heap out-of-bounds write in radare2 PYC parser
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal readers accepted a 32-bit string length without rejecting values that overflow the size-plus-one allocation. The vulnerability is triggered by opening or inspecting a crafted .pyc file through r2 or rabin2. A length of 0xffffffff wrapped the allocation to zero before the common byte reader wrote attacker-controlled data and fill bytes beyond the heap allocation. This can cause heap memory corruption and denial of service; arbitrary code execution is possible but has not been demonstrated. This issue is fixed in version 6.2.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
radare2to a version that resolves this vulnerability.Fixed in 6.2.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of radare2 versions before 6.2.0 are exposed when they open or inspect an attacker-controlled CPython bytecode .pyc file with r2 or rabin2. The attack requires local access and user interaction with the crafted file.
What is the practical impact of successful exploitation?
A crafted .pyc file can corrupt heap memory and cause a denial of service. Arbitrary code execution is considered possible, but it has not been demonstrated.
How can I remediate the vulnerability?
Upgrade radare2 to version 6.2.0, which fixes the overflow in the CPython marshal parser.
What can be done before upgrading?
Do not open or inspect untrusted .pyc files using r2 or rabin2. Restrict analysis to files from trusted sources until the upgrade is complete.