{"id":"CVE-2021-43814","details":"Rizin is a UNIX-like reverse engineering framework and command-line toolset. In versions up to and including 0.3.1 there is a heap-based out of bounds write in parse_die() when reversing an AMD64 ELF binary with DWARF debug info. When a malicious AMD64 ELF binary is opened by a victim user, Rizin may crash or execute unintended actions. No workaround are known and users are advised to upgrade.","aliases":["GHSA-hqqp-vjcm-mw8r"],"modified":"2026-08-07T19:46:59.201170Z","published":"2021-12-13T20:15:07.640Z","references":[{"type":"ADVISORY","url":"https://github.com/rizinorg/rizin/issues/2083"},{"type":"ADVISORY","url":"https://github.com/rizinorg/rizin/security/advisories/GHSA-hqqp-vjcm-mw8r"},{"type":"FIX","url":"https://github.com/rizinorg/rizin/commit/aa6917772d2f32e5a7daab25a46c72df0b5ea406"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rizinorg/rizin","events":[{"introduced":"0"},{"last_affected":"6ef55aa63a563864774f4777dcd1a69933b62a72"},{"fixed":"aa6917772d2f32e5a7daab25a46c72df0b5ea406"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:rizin:rizin:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.3.1"}]}}],"versions":["v0.3.1","v0.3.0","v0.2.1","v0.2.0","v0.1.2","v0.1.1","v0.1.0","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43814.json","vanir_signatures_modified":"2026-08-07T19:46:59Z","vanir_signatures":[{"source":"https://github.com/rizinorg/rizin/commit/aa6917772d2f32e5a7daab25a46c72df0b5ea406","target":{"file":"librz/bin/dwarf.c","function":"init_die"},"deprecated":false,"digest":{"function_hash":"184946763407743022440601383711130511345","length":318},"id":"CVE-2021-43814-07deded8","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["171946936285818130203829138916687425606","155392356072842539040641871064869440824","108810878848874356048509395617253116299","15985135912317706970131247717054542017","105008056566433135516283557564091710069","211586272888071465271238932326398938439","220652809728302332013342877163635112130","208321926003742254237572581827785273579","169318641771539373432137790962547172679","64206610611324884534206476519567992523","80194050254231123193342494689613942651","128645928682106217104578686639896713356","9670304221076258021105079028600091643","232872363258518537691122426263530681166","338653745380197531107530713057209491546","130882101396445514098435889893925001569","222420456810984125243754093713299076856","206324330596012986101210398358147096288","286242271356782261242154970556816375037","58559440571746246767186048242628164209","195922458555335183653931091652688068468","138040944904516051450037403471016540945","92117192771292488363151915803235497222","111641847976220110938756438541456333546","339128023331091000090433989917573654817"],"threshold":0.9},"id":"CVE-2021-43814-272eb637","signature_type":"Line","signature_version":"v1","source":"https://github.com/rizinorg/rizin/commit/aa6917772d2f32e5a7daab25a46c72df0b5ea406","target":{"file":"librz/bin/dwarf.c"}},{"source":"https://github.com/rizinorg/rizin/commit/aa6917772d2f32e5a7daab25a46c72df0b5ea406","target":{"file":"librz/bin/dwarf.c","function":"parse_die"},"deprecated":false,"digest":{"function_hash":"156499722868420146230202167294282105014","length":1173},"id":"CVE-2021-43814-affc1a39","signature_type":"Function","signature_version":"v1"}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}