CVE-2026-8696: radare2 6.1.5 Use-After-Free via gdbr_pids_list()

Published May 15, 2026
·
Updated

radare2 6.1.5 contains a use-after-free vulnerability in the gdbrpidslist() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed thread information responses. Attackers can trigger the vulnerability by causing qsThreadInfo to fail after qfThreadInfo successfully allocates RDebugPid structures, resulting in double-free memory corruption when the error path attempts to clean up the list.

Affected Software

2 affected components
Radare2 Radare2=6.1.5
Radare Radare2<=6.1.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove radare2 from your environment.

    Uninstall radare2 6.1.5 or otherwise stop using this vulnerable build until a patched/fixed version is made available.

  2. Compensating control

    Prevent radare2 from communicating with untrusted remote GDB servers and block or restrict network access that could deliver malformed thread information responses (e.g., via firewall rules, network ACLs, or host-based firewall) to avoid triggering the gdbr_pids_list() use-after-free.

Event History

May 15, 2026
CVE Published
via MITRE·08:52 PM
Data Sourced
via MITRE·08:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 29, 58424
Event
via FIRST·06:08 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-8696?

CVE-2026-8696 is classified as a high severity vulnerability due to its potential for remote denial of service and arbitrary code execution.

2

How do I fix CVE-2026-8696?

To fix CVE-2026-8696, update radare2 to version 6.1.6 or later, which contains the necessary patches.

3

What is the impact of CVE-2026-8696?

The impact of CVE-2026-8696 includes the potential for remote attackers to crash the application or execute arbitrary code.

4

Who is affected by CVE-2026-8696?

CVE-2026-8696 affects users running radare2 version 6.1.5.

5

What is the nature of the vulnerability in CVE-2026-8696?

CVE-2026-8696 is a use-after-free vulnerability found in the gdbr_pids_list() function of radare2.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203