The relocs function in libr/bin/p/bin_bflt.c in radare2 1.2.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6194.json"