REDHAT-BUG-1959939: Double Free
In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.
Reference: https://github.com/radareorg/radare2/issues/18679
Upstream patch: https://github.com/radareorg/radare2/commit/049de62730f4954ef9a642f2eeebbca30a8eccdc
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1959939?
The severity of REDHAT-BUG-1959939 is considered high due to its potential to cause denial of service.
How do I fix REDHAT-BUG-1959939?
To fix REDHAT-BUG-1959939, you should upgrade to a version of radare2 newer than 5.3.0 where the vulnerability has been patched.
What triggers the vulnerability in REDHAT-BUG-1959939?
The vulnerability in REDHAT-BUG-1959939 is triggered by parsing a crafted file in radare2.
What are the consequences of exploiting REDHAT-BUG-1959939?
Exploiting REDHAT-BUG-1959939 can lead to a denial of service, making the application unresponsive.
Which versions of radare2 are affected by REDHAT-BUG-1959939?
Versions of radare2 up to and including 5.3.0 are affected by REDHAT-BUG-1959939.