A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. It is suggested to install a patch to address this issue.
References
| Link | Resource |
|---|---|
| https://github.com/radareorg/radare2/ | Product |
| https://github.com/radareorg/radare2/issues/26041 | Exploit Issue Tracking |
| https://vuldb.com/cve/CVE-2026-14757 | Third Party Advisory VDB Entry |
| https://vuldb.com/submit/850381 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/376346 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/376346/cti | Permissions Required VDB Entry |
Configurations
History
07 Jul 2026, 22:46
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/radareorg/radare2/ - Product | |
| References | () https://github.com/radareorg/radare2/issues/26041 - Exploit, Issue Tracking | |
| References | () https://vuldb.com/cve/CVE-2026-14757 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/submit/850381 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/376346 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/376346/cti - Permissions Required, VDB Entry | |
| First Time |
Radare
Radare radare2 |
|
| CPE | cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:* |
05 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-05 15:16
Updated : 2026-07-07 22:46
NVD link : CVE-2026-14757
Mitre link : CVE-2026-14757
CVE.ORG link : CVE-2026-14757
JSON object : View
Products Affected
radare
- radare2
