CVE-2026-4174

Description

A flaw was found in Radare2. A local attacker could exploit a vulnerability in the Mach-O File Parser component, specifically within the walk_exports_trie function. By manipulating this component, an attacker can cause excessive resource consumption, potentially leading to a Denial of Service (DoS). An exploit for this issue has been publicly disclosed.

Statement

This MODERATE impact vulnerability in Radare2 allows a local attacker to cause resource consumption by manipulating Mach-O files. The flaw affects the walk_exports_trie function within the Mach-O File Parser component. Exploitation requires local access to the system.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other); Reduce Performance

This issue can make the product perform more slowly. If an attacker can influence the number of iterations in the loop, then this performance problem might allow a denial of service by consuming more platform resources than intended.

Frequently Asked Questions

Want to get errata notifications? Sign up here.