{"id":"CVE-2024-31670","details":"rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf functions in librz/bin/format/mach0/dyldcache.c.","modified":"2026-08-12T15:15:12.126991Z","published":"2024-12-12T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/31xxx/CVE-2024-31670.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/31xxx/CVE-2024-31670.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-31670"},{"type":"FIX","url":"https://github.com/rizinorg/rizin/commit/75bac3088b2ec173e22d4be9d525ceacc987cf02"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rizinorg/rizin","events":[{"introduced":"0"},{"fixed":"36a1bf3ec837dd74e4829a6535f2cab349fd4ad2"},{"fixed":"75bac3088b2ec173e22d4be9d525ceacc987cf02"}],"database_specific":{"cpe":"cpe:2.3:a:rizin:rizin:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.6.3"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v0.6.2","v0.6.1","v0.6.0","v0.5.2","v0.5.1","v0.5.0","v0.4.1","v0.4.0","v0.3.4","v0.3.3","v0.3.2","v0.3.1","v0.3.0","v0.2.1","v0.2.0","v0.1.2","v0.1.1","v0.1.0","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-31670.json","vanir_signatures_modified":"2026-08-12T15:15:12Z","vanir_signatures":[{"deprecated":false,"digest":{"length":609,"function_hash":"58262868138063189452359665451193502768"},"id":"CVE-2024-31670-832ca766","signature_type":"Function","signature_version":"v1","source":"https://github.com/rizinorg/rizin/commit/75bac3088b2ec173e22d4be9d525ceacc987cf02","target":{"file":"librz/bin/format/mach0/dyldcache.c","function":"rz_dyldcache_new_buf"}},{"deprecated":false,"digest":{"function_hash":"314028342897745400195669508889791448972","length":841},"id":"CVE-2024-31670-8873be87","signature_type":"Function","signature_version":"v1","source":"https://github.com/rizinorg/rizin/commit/75bac3088b2ec173e22d4be9d525ceacc987cf02","target":{"file":"librz/bin/format/mach0/dyldcache.c","function":"read_cache_accel"}},{"signature_version":"v1","source":"https://github.com/rizinorg/rizin/commit/75bac3088b2ec173e22d4be9d525ceacc987cf02","target":{"file":"librz/bin/format/mach0/dyldcache.c","function":"create_cache_bins"},"deprecated":false,"digest":{"function_hash":"256695099205391455690157599532580480837","length":3758},"id":"CVE-2024-31670-a6a5bca6","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/rizinorg/rizin/commit/75bac3088b2ec173e22d4be9d525ceacc987cf02","target":{"file":"librz/bin/format/mach0/dyldcache.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["260169637974387149379128062662532549875","313930794252959565929684113640467952005","282447215717882830671433862531634236563","100655825308428834543970681936620606390","18772926460710974742276859374737556714","124943200428514757914050311129412486563","263782245906525260577087265545251738762","234285395805901954516181059530364893616","271181938578679421927994831413655718277","123759436810096849085359356080358122409","125644714855743244835571021889880452766","176567526503691916335638984576910704820","120625257675922998548265677636227844417","20531873999069567496068474870587776327","31540796248795974536599264825095925742","293266930025055816019316443172094513387","289570638440673542928992983621587834347","154583043707244852992864084022024124709","120234637199861574248704031023554497610","13096946032531602271589297050430756586"]},"id":"CVE-2024-31670-bce595a4","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}]}