{"id":"CVE-2017-16357","details":"In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to improper sh_size validation when allocating memory.","modified":"2026-08-07T15:18:37.309141Z","published":"2017-11-01T17:29:00.387Z","references":[{"type":"FIX","url":"https://github.com/radare/radare2/commit/0b973e28166636e0ff1fad80baa0385c9c09c53a"},{"type":"FIX","url":"https://github.com/radare/radare2/issues/8742"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/radareorg/radare2","events":[{"introduced":"81aee52168e1b33fd35753bc696693d626b5456c"},{"last_affected":"81aee52168e1b33fd35753bc696693d626b5456c"},{"fixed":"0b973e28166636e0ff1fad80baa0385c9c09c53a"}],"database_specific":{"extracted_events":[{"introduced":"2.0.1"},{"last_affected":"2.0.1"}],"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:radare:radare2:2.0.1:*:*:*:*:*:*:*"}}],"versions":["2.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-16357.json","vanir_signatures_modified":"2026-08-07T15:18:37Z","vanir_signatures":[{"source":"https://github.com/radareorg/radare2/commit/0b973e28166636e0ff1fad80baa0385c9c09c53a","target":{"file":"libr/bin/format/elf/elf.c"},"deprecated":false,"digest":{"line_hashes":["26692998479759459870013215622727912358","288652979355535031639549882948537603259","3782544093117652794349772430380255745","152730329599735831943780152985601448499","294087882619369997535037685605725007832","54527084073341404061289036060863223399","320262521149102359878396703710251788389","123488804540370872185264921454526591900"],"threshold":0.9},"id":"CVE-2017-16357-06d4d10c","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}