Source: radare2
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for radare2.

CVE-2025-63745[0]:
| A NULL pointer dereference vulnerability was discovered in radare2
| 6.0.5 and earlier within the info() function of bin_ne.c. A crafted
| binary input can trigger a segmentation fault, leading to a denial
| of service when the tool processes malformed data.

https://github.com/radareorg/radare2/issues/24660
Fixed by: 
https://github.com/radareorg/radare2/commit/6c5df3f8570d4f0c360681c08241ad8af3b919fd
                 

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-63745
    https://www.cve.org/CVERecord?id=CVE-2025-63745

Please adjust the affected versions in the BTS as needed.

Reply via email to