{"id":"CVE-2026-14788","summary":"radareorg radare2 cfile.c r_core_bin_load use after free","details":"A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The name of the patch is 635ab1eeb30340c26076722a90cb91fb2272130b. Applying a patch is advised to resolve this issue.","modified":"2026-08-12T16:24:51.490258Z","published":"2026-07-06T01:45:08.467Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14788.json","unresolved_ranges":[{"extracted_events":[{"introduced":"6.1.1"},{"last_affected":"6.1.1"},{"introduced":"6.1.3"},{"last_affected":"6.1.3"},{"introduced":"6.1.5"},{"last_affected":"6.1.5"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/radareorg/radare2/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14788.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14788"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-14788"},{"type":"ADVISORY","url":"https://vuldb.com/submit/850388"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/376377"},{"type":"REPORT","url":"https://github.com/radareorg/radare2/issues/26049"},{"type":"REPORT","url":"https://vuldb.com/vuln/376377/cti"},{"type":"FIX","url":"https://github.com/oldzhu/radare2/commit/635ab1eeb30340c26076722a90cb91fb2272130b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/oldzhu/radare2","events":[{"introduced":"0"},{"fixed":"635ab1eeb30340c26076722a90cb91fb2272130b"}],"database_specific":{"source":"REFERENCES"}},{"type":"GIT","repo":"https://github.com/radareorg/radare2","events":[{"introduced":"c3d11822fde49cbc9af338bbc54ad050d00f8a80"},{"last_affected":"a930bac5d511854a3b78ffd4bd94ff2971cff978"}],"database_specific":{"extracted_events":[{"introduced":"6.1.0"},{"last_affected":"6.1.0"},{"introduced":"6.1.2"},{"last_affected":"6.1.2"},{"introduced":"6.1.4"},{"last_affected":"6.1.4"},{"introduced":"6.1.6"},{"last_affected":"6.1.6"}],"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:*"}}],"versions":["6.1.0","6.1.2","6.1.4","6.1.6","5.4.0","5.4.0-git","5.3.1","5.3.0","5.2.1","5.2.0","5.1.1","5.1.0","release-5.0.0","5.0.0","continuous","4.5.1","4.4.0","4.3.1","Continuous-Windows","4.3.0","4.2.1","4.2.0","4.1.1","4.1.0","4.0.0","3.9.0","3.8.0","3.7.1","3.7.0","3.6.0","3.5.1","3.5.0","3.4.1","3.4.0","3.3.0","3.2.1","3.2.0","3.1.3","3.1.2","3.1.1","3.1.0","3.0.1","3.0.0","2.9.0","2.8.0","2.7.0","2.6.9","2.6.0","2.5.0","2.4.0","2.2.0","2.1.0","2.0.1","2.0.0","1.6.0","1.5.0","1.4.0","1.3.0","1.3.0-git","1.2.0","1.2.0-git","1.1.0","1.0.2","1.0.1","1.0.0","1.0","0.10.6","0.10.5","0.10.4-termux4","termux","0.10.4","0.10.3","0.10.2","0.10.1","0.10.0","radare2-windows-nightly","0.9.9","0.9.8","0.9.8-rc4","0.9.8-rc3","0.9.8-rc2","0.9.8-rc1","0.9.7","0.9.6","0.9.4","0.9.2","0.9","0.8.8","0.8.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14788.json","vanir_signatures_modified":"2026-08-12T16:24:51Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["283709474811596500726525919875503922077","217254216008757294463104534361266500518","94842876956472592692018913350907135152","37706881606926451107114925427191270747","107979096265912935910867782733776028879","295189447693616992196994778964525091122","16374194733092419997069333773555593405","136613621528255535728531000450009220428","323908330817801538103897511239075927113","206652694388015576038802360850224092000","32927927206208473068438141207729948558","264434196235807501429277516007627661644","11701182670190057040523570194110334022","240127647656535295405309267997383483251","34711853816782412623365273603885761522","115713092543486095507134920656533373604","84598516366292868121164063049224947792","216134292334708428030008415582676537399","151848943117262697608975638600885949385","326050179381026709624885652969791805346","266347401985585315466031150307169650940","170377904178525560292616072537210475530","92536531342988750654212120281174300354","236094016804717980651158982693453432596","160522412378303849467294090836212247576","228303549990805055390919004599522625034","198877025125015747120528258532953375403","267121313372286285301249101074752402784","234699187975066989940397057811535727825","300171105538948007972040061250327759908","227128321983746073071327343602898069825","146062550926445486654160434816441187759","310821921828989747334743629470834201395"],"threshold":0.9},"id":"CVE-2026-14788-1b35c7dd","signature_type":"Line","signature_version":"v1","source":"https://github.com/oldzhu/radare2/commit/635ab1eeb30340c26076722a90cb91fb2272130b","target":{"file":"libr/core/cfile.c"}},{"deprecated":false,"digest":{"function_hash":"288484916071129260340861275169036169979","length":7289},"id":"CVE-2026-14788-56555ac0","signature_type":"Function","signature_version":"v1","source":"https://github.com/oldzhu/radare2/commit/635ab1eeb30340c26076722a90cb91fb2272130b","target":{"file":"libr/core/cfile.c","function":"r_core_bin_load"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}