{"id":"CVE-2018-11376","details":"The r_read_le32() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file.","modified":"2026-08-07T14:54:06.663915Z","published":"2018-05-22T19:29:00.270Z","references":[{"type":"ADVISORY","url":"https://github.com/radare/radare2/issues/9904"},{"type":"FIX","url":"https://github.com/radare/radare2/commit/1f37c04f2a762500222dda2459e6a04646feeedf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/radareorg/radare2","events":[{"introduced":"c2b7d11ca74cd98eba8912d94ec0973cf2965697"},{"last_affected":"c2b7d11ca74cd98eba8912d94ec0973cf2965697"},{"fixed":"1f37c04f2a762500222dda2459e6a04646feeedf"}],"database_specific":{"cpe":"cpe:2.3:a:radare:radare2:2.5.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.5.0"},{"last_affected":"2.5.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["2.5.0"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["74147868421164778536266043603420534155","94012138497178765259711521921749933602","127318990783415709744242895765158527360","127253702788854721694552368469173099888"],"threshold":0.9},"id":"CVE-2018-11376-1236e4bf","signature_type":"Line","signature_version":"v1","source":"https://github.com/radareorg/radare2/commit/1f37c04f2a762500222dda2459e6a04646feeedf","target":{"file":"libr/core/cbin.c"}},{"target":{"file":"libr/core/cbin.c","function":"bin_entry"},"deprecated":false,"digest":{"function_hash":"268876414047930744123853343933127487284","length":3340},"id":"CVE-2018-11376-a48149a5","signature_type":"Function","signature_version":"v1","source":"https://github.com/radareorg/radare2/commit/1f37c04f2a762500222dda2459e6a04646feeedf"},{"source":"https://github.com/radareorg/radare2/commit/1f37c04f2a762500222dda2459e6a04646feeedf","target":{"file":"libr/bin/p/bin_elf.c"},"deprecated":false,"digest":{"line_hashes":["239465907582288234478493190199706323560","265047590234715799993876434927710511677","73638889202388708246382006019522487151","203492581216947726462311589824830531931","111223670578665787765158084771167683025","310554751992119742824921622046783105906","244373275692055250934245746795551528343","144292358253911142672534763828864318582"],"threshold":0.9},"id":"CVE-2018-11376-bf0ed46e","signature_type":"Line","signature_version":"v1"},{"source":"https://github.com/radareorg/radare2/commit/1f37c04f2a762500222dda2459e6a04646feeedf","target":{"file":"libr/bin/p/bin_elf.c","function":"process_constructors"},"deprecated":false,"digest":{"length":1117,"function_hash":"192691691577455363091545508820585713191"},"id":"CVE-2018-11376-d254ef0b","signature_type":"Function","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11376.json","vanir_signatures_modified":"2026-08-07T14:54:06Z"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}