<Vulnerability name="CVE-2026-14757">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-07-05T14:45:07</PublicDate>
    <Bugzilla id="2497164" url="https://bugzilla.redhat.com/show_bug.cgi?id=2497164" xml:lang="en:us">
radare2: Radare2: Integer overflow allows local impact
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-190</CWE>
    <Details xml:lang="en:us" source="Mitre">
A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. It is suggested to install a patch to address this issue.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in radareorg radare2. A local attacker could exploit an integer overflow vulnerability within the `core_anal_bytes` function. This manipulation could lead to limited impacts on confidentiality, integrity, and availability of the system.
    </Details>
    <Statement xml:lang="en:us">
This Moderate impact flaw in radare2 allows a local attacker to trigger an integer overflow within the `core_anal_bytes` function. Exploitation requires local access to the system and could lead to limited impacts on data confidentiality, integrity, and system availability.
    </Statement>
    <Mitigation xml:lang="en:us">
To mitigate this issue, users should exercise caution when processing untrusted or maliciously crafted files with radare2. Avoid opening or analyzing files from unknown or unverified sources. Additionally, consider running radare2 within a sandboxed environment, such as a container or a restricted user account, to further limit the potential impact of exploitation.
    </Mitigation>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-14757
https://nvd.nist.gov/vuln/detail/CVE-2026-14757
https://github.com/radareorg/radare2/
https://github.com/radareorg/radare2/issues/26041
https://vuldb.com/cve/CVE-2026-14757
https://vuldb.com/submit/850381
https://vuldb.com/vuln/376346
https://vuldb.com/vuln/376346/cti
    </References>
</Vulnerability>