← back
CVE-2022-0173criticalCWE-125

Out-of-bounds Read in radareorg/radare2

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.6epss 1.1%
exploitation probability
1.1%top 35% of all CVEs
observed exploitation
nono source reports it
In short

radare2 has a flaw that allows reading memory beyond its intended boundaries, potentially exposing sensitive data or causing the program to crash. This occurs when the software processes specially crafted input without proper validation.

Technical detail

Out-of-bounds read vulnerability (CWE-125) in radare2 allows an attacker to read memory outside allocated buffers by providing malformed input. The vulnerability requires local or remote input processing depending on the attack vector, and impacts confidentiality through information disclosure or availability through denial of service.

Summary generated and translated by AI from the official description.
radare2 is vulnerable to Out-of-bounds Read
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H