CVE-2026-14760

A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:*

History

07 Jul 2026, 22:30

Type Values Removed Values Added
References () https://github.com/radareorg/radare2/ - () https://github.com/radareorg/radare2/ - Product
References () https://github.com/radareorg/radare2/commit/8b25c773785d85cb0103410a0905089d286921c2 - () https://github.com/radareorg/radare2/commit/8b25c773785d85cb0103410a0905089d286921c2 - Patch
References () https://github.com/radareorg/radare2/issues/26044 - () https://github.com/radareorg/radare2/issues/26044 - Exploit, Issue Tracking
References () https://vuldb.com/cve/CVE-2026-14760 - () https://vuldb.com/cve/CVE-2026-14760 - Third Party Advisory, VDB Entry
References () https://vuldb.com/submit/850384 - () https://vuldb.com/submit/850384 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/376349 - () https://vuldb.com/vuln/376349 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/376349/cti - () https://vuldb.com/vuln/376349/cti - Permissions Required, VDB Entry
CPE cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:*
First Time Radare
Radare radare2

06 Jul 2026, 17:16

Type Values Removed Values Added
References () https://vuldb.com/submit/850384 - () https://vuldb.com/submit/850384 -

05 Jul 2026, 16:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-05 16:19

Updated : 2026-07-09 15:47


NVD link : CVE-2026-14760

Mitre link : CVE-2026-14760

CVE.ORG link : CVE-2026-14760


JSON object : View

Products Affected

radare

  • radare2
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-416

Use After Free