{"id":"CVE-2026-81886","summary":"radare2: Uncontrolled memory allocation in radare2 dmp64 parser","details":"radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 parser used an input-controlled physical-memory-run PageCount directly as the bound of a per-page allocation loop. The vulnerability is triggered by opening a small crafted full-memory Windows crash dump. The parser repeatedly allocated and appended page descriptors without validating the count against the dump size. This can cause denial of service through excessive memory consumption and processing time. This issue is fixed in version 6.2.0.","aliases":["GHSA-3xrx-wh64-8xr8"],"modified":"2026-09-24T08:26:10.246644Z","published":"2026-09-22T15:11:36.343Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81886.json"},"references":[{"type":"WEB","url":"https://github.com/radareorg/radare2/releases/tag/6.2.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81886.json"},{"type":"ADVISORY","url":"https://github.com/radareorg/radare2/security/advisories/GHSA-3xrx-wh64-8xr8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81886"},{"type":"REPORT","url":"https://github.com/radareorg/radare2/issues/26224"},{"type":"FIX","url":"https://github.com/radareorg/radare2/commit/a7519fdb4da6835c2cecd8fe248e7dd1133cf17a"},{"type":"FIX","url":"https://github.com/radareorg/radare2/pull/26180"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/radareorg/radare2","events":[{"introduced":"0"},{"fixed":"a7519fdb4da6835c2cecd8fe248e7dd1133cf17a"},{"fixed":"e1fc278734ad62f933fc6f91edb29e4ba732f402"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"6.2.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["6.1.8","6.1.6","6.1.4","6.1.2","6.1.0","6.0.8","6.0.7","6.0.6","6.0.4","6.0.2","6.0.0","5.9.8","5.9.6","5.9.4","5.9.2","5.9.0","5.8.8","5.8.6","5.8.4","5.8.2","5.8.0","5.7.8","5.7.6","5.7.4","5.7.2","5.7.0","wip","5.6.8","5.6.6","5.6.4","5.6.2","5.6.0","5.5.4","5.5.2","5.5.0","5.4.2","5.4.0","5.4.0-git","5.3.1","5.3.0","5.2.1","5.2.0","5.1.1","5.1.0","release-5.0.0","5.0.0","4.5.1","4.4.0","4.3.1","Continuous-Windows","4.3.0","continuous","4.2.1","4.2.0","4.1.1","4.1.0","4.0.0","3.9.0","3.8.0","3.7.1","3.7.0","3.6.0","3.5.1","3.5.0","3.4.1","3.4.0","3.3.0","3.2.1","3.2.0","3.1.3","3.1.2","3.1.1","3.1.0","3.0.1","3.0.0","2.9.0","2.8.0","2.7.0","2.6.9","2.6.0","2.5.0","2.4.0","2.2.0","2.1.0","2.0.1","2.0.0","1.6.0","1.5.0","1.4.0","1.3.0","1.3.0-git","1.2.0","1.2.0-git","1.1.0","1.0.2","1.0.1","1.0.0","1.0","0.10.6","0.10.5","0.10.4-termux4","termux","0.10.4","0.10.3","0.10.2","0.10.1","0.10.0","radare2-windows-nightly","0.9.9","0.9.8","0.9.8-rc4","0.9.8-rc3","0.9.8-rc2","0.9.8-rc1","0.9.7","0.9.6","0.9.4","0.9.2","0.9","0.8.8","0.8.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81886.json","vanir_signatures_modified":"2026-09-24T08:26:10Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"41316783888030046758025943781620388516","length":282},"id":"CVE-2026-81886-00f21a1c","signature_type":"Function","signature_version":"v1","source":"https://github.com/radareorg/radare2/commit/a7519fdb4da6835c2cecd8fe248e7dd1133cf17a","target":{"file":"libr/bin/format/dmp/dmp64.c","function":"r_bin_dmp64_new_buf"}},{"source":"https://github.com/radareorg/radare2/commit/a7519fdb4da6835c2cecd8fe248e7dd1133cf17a","target":{"file":"libr/bin/format/dmp/dmp64.c","function":"r_bin_dmp64_init_header"},"deprecated":false,"digest":{"function_hash":"319453721259206446956400049733302426953","length":1037},"id":"CVE-2026-81886-1490b50b","signature_type":"Function","signature_version":"v1"},{"source":"https://github.com/radareorg/radare2/commit/a7519fdb4da6835c2cecd8fe248e7dd1133cf17a","target":{"file":"libr/bin/format/dmp/dmp64.c","function":"r_bin_dmp64_init_bmp_pages"},"deprecated":false,"digest":{"function_hash":"248426322675063164864366042527423336301","length":1006},"id":"CVE-2026-81886-6249a98b","signature_type":"Function","signature_version":"v1"},{"source":"https://github.com/radareorg/radare2/commit/a7519fdb4da6835c2cecd8fe248e7dd1133cf17a","target":{"file":"libr/bin/format/dmp/dmp64.c"},"deprecated":false,"digest":{"line_hashes":["211620872248411714255462369859912971288","260817871685571556395747891513665150113","132272182908975065723357376451527520916","27147078729171150585144287595074066074","178830795855964668071082360254269946241","232633201061213769520989672871392330119","179695752008748097619660286567197934258","114529045290806023847551830381284648417","310634751472857222980565724132741850256","111865618225184348107455552997842195599","300017672043404274845444535749704494041","322070639159749808533622463183813896202","285239134564547346020874575939877547321","255365200606758366313397299789849521141","311003787763053496687117039456967401414","221748197784804328531986232271097803185","218949253243695046467577118616348881073","299505519031657362749432878670147585224","258170043542081583914414392040800625870","69117688228030805565036341952208746386","240345660983891155328588381986558010752","322064945855538785730988924145988422890","258410175021606854625437937261020279269","116606985704196405125068083721799536430","195246376356604063379860918619005199038","298675079987312632259296532566764100605","17354785539702781075196919753627555841","270743212037692320136344617475925696512","257632390997208316397435210436119831585","327622622964181546095242557507434947392","251194683203904028679745077118435156382","229424844173014161215746095543229567596","312182223518705583946843526524671672194","115818476631479831453244963665903527313","188011868846549760613021935774710524149","125380355741459911698584649304244229662","29471428158870207530672688063773203595","132103863353255858812355807630424535273","207095756473929915382871437573916812782","24228472306361672661502313277804064765","298395876585915528477871549270421392151","290332808341989607618343676455491681325","2373086147400029045582182270371157569","138042801121013125721504513648160830760","212709972737446000600240254471952209101","29864561521335087471771478195852025889","35923143071543642984031333161672630573","98830682026977360611483963105424036075","122040259776693262051769607060089191710","195891979350067794044132845141041012036","235811882305488279125504851907439923553","169158907468920547840546523610091222669","171800667492047971309151479193443271018","128594750796466845696700090161023011554","137637570400787898119557576176295124270","262943785792059581781219888896437024283","198431290152879925643320557585541773575","149566538967927069392634153681600647072","79021314100875507444603384736800572891","172002138259593868163540807047238642132","239528936343794506544689798816890740329","232242538264352854175220881378691613627","149316519929489075053392288233606701363","142572704870587585323006032682472315527","228110142197512899004587406003631852354","280694445033220333213639263355720121518","336098540654891174885375981364056289505","82685154875761572944944267730043371091","228524363360787665827222588564476342256","148551961742081392250584612997662638559","63094179125190559645215548611283617430","214071989817190474834226912750290217746","47813474613777215633826245942554800708","261520036839734082581880596542377503329","199170132740875075055651794849940089466"],"threshold":0.9},"id":"CVE-2026-81886-7ba8a942","signature_type":"Line","signature_version":"v1"},{"digest":{"function_hash":"209586717615332746838989879966145793746","length":1258},"id":"CVE-2026-81886-84d57ea8","signature_type":"Function","signature_version":"v1","source":"https://github.com/radareorg/radare2/commit/a7519fdb4da6835c2cecd8fe248e7dd1133cf17a","target":{"function":"r_bin_dmp64_init_bmp_header","file":"libr/bin/format/dmp/dmp64.c"},"deprecated":false},{"id":"CVE-2026-81886-8abcb83d","signature_type":"Function","signature_version":"v1","source":"https://github.com/radareorg/radare2/commit/a7519fdb4da6835c2cecd8fe248e7dd1133cf17a","target":{"file":"libr/bin/format/dmp/dmp64.c","function":"r_bin_dmp64_init_memory_runs"},"deprecated":false,"digest":{"function_hash":"112826621970189603576743516838750281950","length":1359}},{"source":"https://github.com/radareorg/radare2/commit/a7519fdb4da6835c2cecd8fe248e7dd1133cf17a","target":{"file":"libr/bin/format/dmp/dmp64.c","function":"r_bin_dmp64_init"},"deprecated":false,"digest":{"function_hash":"238714874456578799819182826122498093561","length":410},"id":"CVE-2026-81886-af28a7c2","signature_type":"Function","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}