<Vulnerability name="CVE-2026-14788">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Low</ThreatSeverity>
    <PublicDate>2026-07-06T01:45:08</PublicDate>
    <Bugzilla id="2497219" url="https://bugzilla.redhat.com/show_bug.cgi?id=2497219" xml:lang="en:us">
radare2: radare2: Denial of Service via use-after-free in r_core_bin_load function
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>3.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-825</CWE>
    <Details xml:lang="en:us" source="Mitre">
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The name of the patch is 635ab1eeb30340c26076722a90cb91fb2272130b. Applying a patch is advised to resolve this issue.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in radare2. A local attacker could trigger a use-after-free vulnerability within the r_core_bin_load function. This issue can lead to memory corruption, resulting in a denial of service (DoS) for the application.
    </Details>
    <Statement xml:lang="en:us">
This Low impact flaw in radare2, a reverse engineering framework, allows a local attacker to cause a denial of service. The use-after-free vulnerability in the r_core_bin_load function requires local access and specific interaction with the tool, limiting its broader system impact on typical Red Hat deployments.
    </Statement>
    <Mitigation xml:lang="en:us">
To mitigate this issue, ensure that only trusted users have local access to systems where the `radare2` package is installed. If `radare2` is not required, consider removing the package to eliminate the potential for exploitation.
    </Mitigation>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-14788
https://nvd.nist.gov/vuln/detail/CVE-2026-14788
https://github.com/oldzhu/radare2/commit/635ab1eeb30340c26076722a90cb91fb2272130b
https://github.com/radareorg/radare2/
https://github.com/radareorg/radare2/issues/26049
https://vuldb.com/cve/CVE-2026-14788
https://vuldb.com/submit/850388
https://vuldb.com/vuln/376377
https://vuldb.com/vuln/376377/cti
    </References>
</Vulnerability>