{"id":"openSUSE-SU-2026:21988-1","summary":"Security update for radare2","details":"This update for radare2 fixes the following issues:\n\nChanges in radare2:\n\n- Update to version 6.2.2:\n  * Analysis: new JNI plugin with typed interface tables, arm64\n    Swift float calling conventions, DWARF prototype linking,\n    jump-table and switch-case fixes\n  * Core: fix RAnalOp leaks in disasm/diff/debug loops, aoj memory\n    use, partial-read handling, fp variable recovery\n  * Bundle sdb 2.5.2 (upstream pin): rename shlib to libsdb2_5_2\n  * Details can be found here:\n    https://github.com/radareorg/radare2/releases/tag/6.2.2\n\n- Security issues fixed:\n  * CVE-2026-81886: Validate dmp64 page counts against dump size\n    (boo#1282346).\n  * CVE-2026-81885: Fix infinite loop in the NE fixup parser\n    (boo#1282345).\n  * CVE-2026-81884: Validate Mach-O LC_DATA_IN_CODE ranges\n    (boo#1282344).\n  * CVE-2026-81883: Fix Lua function parser OOB reads (boo#1282343).\n  * CVE-2026-81882: Fix bplist Unicode string conversion (boo#1282342).\n  * CVE-2026-81881: Fix Swift Mach-O field metadata bounds check\n    (boo#1282341).\n  * CVE-2026-81880: Decode PEF relocs lazily, add more bounds and\n    overflow checks (boo#1282340).\n  * CVE-2026-81879: Fix oobread in ELF PN_XNUM phdr count handling\n    (boo#1282339).\n  * CVE-2026-81878: Fix heap write overflow in Python loader\n    (boo#1282338).\n  * CVE-2026-14788: Denial of Service via use-after-free in\n    r_core_bin_load function (boo#1270453).\n  * CVE-2026-14761: Denial of service via integer overflow in string\n    manipulation functions (boo#1270452).\n  * CVE-2026-14760: Denial of Service via local use-after-free\n    vulnerability (boo#1270450).\n  * CVE-2026-14759: Denial of Service via heap-based buffer overflow\n    (boo#1270449).\n  * CVE-2026-14758: Denial of Service via integer overflow in hexpairs\n    parser (boo#1270447).\n  * CVE-2026-14757: Integer overflow allows local impact (boo#1270445).\n  * CVE-2026-40527: Command injection vulnerability in the afsv/afsvj\n    (boo#1262336).\n  * CVE-2026-4174: Missing validation against an upper limit when\n    allocating memory in the Mach-O file parser can lead to excessive\n    resource consumption (boo#1259722).\n- Security issue fixed with the previous release:\n  * CVE-2026-41015: Configured on UNIX without SSL, allows command\n    injection via a PDB name to rabin2 (boo#1262190).\n  * CVE-2026-40517: Crafted PDB file with newline characters in symbol\n    names can allow to inject arbitrary commands (boo#1262680).\n  * CVE-2026-8695: UAFs in the gdb remote protocol ##crash (boo#1265403).\n","modified":"2026-10-01T18:23:10.943305024Z","published":"2026-09-25T08:25:52Z","related":["CVE-2026-14757","CVE-2026-14758","CVE-2026-14759","CVE-2026-14760","CVE-2026-14761","CVE-2026-14788","CVE-2026-40517","CVE-2026-40527","CVE-2026-41015","CVE-2026-4174","CVE-2026-81878","CVE-2026-81879","CVE-2026-81880","CVE-2026-81881","CVE-2026-81882","CVE-2026-81883","CVE-2026-81884","CVE-2026-81885","CVE-2026-81886","CVE-2026-8695"],"upstream":["CVE-2026-14757","CVE-2026-14758","CVE-2026-14759","CVE-2026-14760","CVE-2026-14761","CVE-2026-14788","CVE-2026-40517","CVE-2026-40527","CVE-2026-41015","CVE-2026-4174","CVE-2026-81878","CVE-2026-81879","CVE-2026-81880","CVE-2026-81881","CVE-2026-81882","CVE-2026-81883","CVE-2026-81884","CVE-2026-81885","CVE-2026-81886","CVE-2026-8695"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259722"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262190"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262336"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262680"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265403"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270445"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270447"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270449"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270450"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270452"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270453"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282338"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282339"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282340"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282341"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282342"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282343"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282344"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282345"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282346"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14757"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14758"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14759"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14760"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14761"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14788"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40517"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40527"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41015"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4174"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81878"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81879"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81880"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81881"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81882"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81883"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81884"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81885"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81886"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8695"}],"affected":[{"package":{"name":"radare2","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/radare2&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.2.2-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"radare2-devel":"6.2.2-bp160.1.1","radare2-zsh-completion":"6.2.2-bp160.1.1","libsdb2_5_2":"6.2.2-bp160.1.1","radare2":"6.2.2-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21988-1.json"}}],"schema_version":"1.9.0"}