{"id":"CVE-2026-14789","summary":"radareorg radare2 Memory64ListStream mdmp.c stack-based overflow","details":"A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of the file libr/bin/format/mdmp/mdmp.c of the component Memory64ListStream Parser. Performing a manipulation results in stack-based buffer overflow. The attack requires a local approach. The exploit is now public and may be used. The patch is named 175d4addb68981331c85b10681c2161c38fb5762. It is suggested to install a patch to address this issue.","modified":"2026-08-12T15:31:28.031520Z","published":"2026-07-06T02:00:10.294Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14789.json","unresolved_ranges":[{"extracted_events":[{"introduced":"6.1.1"},{"last_affected":"6.1.1"},{"introduced":"6.1.3"},{"last_affected":"6.1.3"},{"introduced":"6.1.5"},{"last_affected":"6.1.5"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-121"]},"references":[{"type":"WEB","url":"https://github.com/radareorg/radare2/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14789.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14789"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-14789"},{"type":"ADVISORY","url":"https://vuldb.com/submit/850389"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/376378"},{"type":"REPORT","url":"https://github.com/radareorg/radare2/issues/26051"},{"type":"REPORT","url":"https://vuldb.com/vuln/376378/cti"},{"type":"FIX","url":"https://github.com/mengzhisuoliu/radare2/commit/175d4addb68981331c85b10681c2161c38fb5762"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mengzhisuoliu/radare2","events":[{"introduced":"0"},{"fixed":"175d4addb68981331c85b10681c2161c38fb5762"}],"database_specific":{"source":"REFERENCES"}},{"type":"GIT","repo":"https://github.com/radareorg/radare2","events":[{"introduced":"c3d11822fde49cbc9af338bbc54ad050d00f8a80"},{"last_affected":"a930bac5d511854a3b78ffd4bd94ff2971cff978"}],"database_specific":{"extracted_events":[{"introduced":"6.1.0"},{"last_affected":"6.1.0"},{"introduced":"6.1.2"},{"last_affected":"6.1.2"},{"introduced":"6.1.4"},{"last_affected":"6.1.4"},{"introduced":"6.1.6"},{"last_affected":"6.1.6"}],"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:*"}}],"versions":["6.1.0","6.1.2","6.1.4","6.1.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14789.json","vanir_signatures_modified":"2026-08-12T15:31:28Z","vanir_signatures":[{"source":"https://github.com/mengzhisuoliu/radare2/commit/175d4addb68981331c85b10681c2161c38fb5762","target":{"file":"libr/bin/format/mdmp/mdmp.c","function":"r_bin_mdmp_init_directory_entry"},"deprecated":false,"digest":{"function_hash":"161530247012240210902198524769450399096","length":15367},"id":"CVE-2026-14789-2589e0b0","signature_type":"Function","signature_version":"v1"},{"source":"https://github.com/mengzhisuoliu/radare2/commit/175d4addb68981331c85b10681c2161c38fb5762","target":{"file":"libr/bin/format/mdmp/mdmp.c"},"deprecated":false,"digest":{"line_hashes":["33735641350358749063429528842775685915","14329994184076394331732556889140379048","242066281863258414182118607133255687135","207846837990236756547636938075108118454","284194595178973650520266953536928984923","285871578208998473368385184647028503292","291963313617328034091193528383801345932","271777200243919316191033525802881297715","246517550443861242465671000451238976110","263988628303913377412861585817276429125","190628331038711915632909063028409573306","323072810266559492257896282991419243647","339591238949312946772372220490138917500","253329205937364817863243683423911676949","191564657236794922328504251308776348376","270589145792979476193730184262623596251","4198168750414086761390115468746501513","209559729191587262969950401558328762472","195219251694274970807709392331445782940","41037906649378037987690197816022203647","217649175824730551991890475528967237855","212981541237277272967661032080293072215","62806470638437306124536178409663803116","299751332663821873633096422042729583062","254511665125530389536192406302863026522","186748821719672146151909311818434954465","236280278178243420763879530085991173305","229988392888623741103232997259733023391","119491971048420515489793840218457357355","87754118020172406844433424337004687940","304040959476469927139091744301979491941","182183068887944104496356061418067594862","299878125746590613427279678076498086482","122738870128567670785953128019107785411","208231075985745549898444450268744662271","191028154764754261239889338319529454097","83445359184813543139979396396703326457","86023457252602330309623749213096298910","250844675271885261689011500046505096252","47284608901802252475967947479919634626"],"threshold":0.9},"id":"CVE-2026-14789-daab1148","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}