216.73.217.22

CVE-2026-8696

· Published 15/05/2026 21:16 · Modified 15/05/2026 21:16

Labels: CVE-2026-8696 2026-05-15CVE-2026-8696CWE-416[email protected]

Essential information

Published
15/05/2026 21:16
Modified
15/05/2026 21:16
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed thread information responses. Attackers can trigger the vulnerability by causing qsThreadInfo to fail after qfThreadInfo successfully allocates RDebugPid structures, resulting in double-free memory corruption when the error path attempts to clean up the list.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
radare2 / radare2 cpe:2.3:a:radare2:radare2:6.1.5:*:*:*:*:*:*:*

References