CVE-2026-22780

Rizin is a UNIX-like reverse engineering framework and command-line toolset. Prior to 0.8.2, a heap overflow can be exploited when a malicious mach0 file, having bogus entries for the dyld chained segments, is parsed by rizin. This vulnerability is fixed in 0.8.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rizin:rizin:*:*:*:*:*:*:*:*

History

20 Feb 2026, 21:12

Type Values Removed Values Added
First Time Rizin
Rizin rizin
CPE cpe:2.3:a:rizin:rizin:*:*:*:*:*:*:*:*
Summary
  • (es) Rizin es un framework de ingeniería inversa y conjunto de herramientas de línea de comandos similar a UNIX. Antes de la 0.8.2, se puede explotar un desbordamiento de montículo cuando un archivo mach0 malicioso, que contiene entradas falsas para los segmentos encadenados de dyld, es analizado por rizin. Esta vulnerabilidad está corregida en la 0.8.2.
References () https://github.com/rizinorg/rizin/blob/6dd0dba9ff4dc706f549d0cdcd93856b49e59aa0/librz/bin/format/mach0/mach0_chained_fixups.c#L200 - () https://github.com/rizinorg/rizin/blob/6dd0dba9ff4dc706f549d0cdcd93856b49e59aa0/librz/bin/format/mach0/mach0_chained_fixups.c#L200 - Patch
References () https://github.com/rizinorg/rizin/commit/41ea75d5b07d9b41b27ae80675cdda65f1b1c989 - () https://github.com/rizinorg/rizin/commit/41ea75d5b07d9b41b27ae80675cdda65f1b1c989 - Patch
References () https://github.com/rizinorg/rizin/issues/5768 - () https://github.com/rizinorg/rizin/issues/5768 - Issue Tracking
References () https://github.com/rizinorg/rizin/pull/5770 - () https://github.com/rizinorg/rizin/pull/5770 - Issue Tracking
References () https://github.com/rizinorg/rizin/releases/tag/v0.8.2 - () https://github.com/rizinorg/rizin/releases/tag/v0.8.2 - Product, Release Notes
References () https://github.com/rizinorg/rizin/security/advisories/GHSA-f3v7-xhmj-9cjj - () https://github.com/rizinorg/rizin/security/advisories/GHSA-f3v7-xhmj-9cjj - Patch, Vendor Advisory

02 Feb 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-02 23:16

Updated : 2026-02-20 21:12


NVD link : CVE-2026-22780

Mitre link : CVE-2026-22780

CVE.ORG link : CVE-2026-22780


JSON object : View

Products Affected

rizin

  • rizin
CWE
CWE-770

Allocation of Resources Without Limits or Throttling