CVE-2026-8695: radare2 6.1.5 Use-After-Free via gdbr_threads_list()

Published May 15, 2026
·
Updated

radare2 6.1.5 contains a use-after-free vulnerability in the gdbrthreadslist() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability through GDB remote debugging to cause a denial of service or potentially achieve code execution by manipulating thread list processing.

Affected Software

2 affected components
Radare2 Radare2=6.1.5
Radare Radare2<=6.1.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove radare2 from your environment.

    Uninstall radare2 or remove/disable components that provide GDB remote debugging if the software is not required until a security fix is available.

  2. Configuration

    Disable radare2's GDB remote debugging support or avoid starting the built-in GDB remote server to prevent processing of qfThreadInfo/qsThreadInfo responses.

    radare2 GDB remote debugging = disabled
  3. Compensating control

    Restrict access to any GDB remote debugging ports or services via firewall/ACLs to trusted management networks only; do not expose GDB remote debugging to untrusted networks.

  4. Compensating control

    Perform GDB remote debugging only within isolated/trusted environments (for example, on an internal VPN or air-gapped network) to reduce exposure to remote attackers.

  5. Operational

    Monitor radare2 project advisories for a security fix and apply vendor-supplied updates when a fixed version is released; until then, avoid enabling GDB remote debugging.

Event History

May 15, 2026
CVE Published
via MITRE·05:01 PM
Data Sourced
via MITRE·05:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 29, 58424
Event
via FIRST·04:01 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-8695?

CVE-2026-8695 is classified as a high-severity vulnerability due to its potential to cause remote memory corruption.

2

How do I fix CVE-2026-8695?

To fix CVE-2026-8695, users should upgrade to radare2 version 6.1.6 or later where the vulnerability is addressed.

3

What is the impact of CVE-2026-8695?

CVE-2026-8695 can allow remote attackers to exploit memory corruption, potentially leading to arbitrary code execution.

4

Who is affected by CVE-2026-8695?

CVE-2026-8695 affects users of radare2 version 6.1.5.

5

What is the cause of CVE-2026-8695?

CVE-2026-8695 is caused by a use-after-free vulnerability in the gdbr_threads_list() function when handling specific responses.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203