In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.
[
{
"source": "https://github.com/radareorg/radare2/commit/a07dedb804a82bc01c07072861942dd80c6b6d62",
"target": {
"file": "libr/bin/p/bin_mach0.c"
},
"digest": {
"line_hashes": [
"211921345178114093370428947692498009900",
"154239016323387656120110791473062974521",
"197634429748365036978182416865077052005",
"211074051710044500989675597504644777329",
"217178479459434555199088203652955891060"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2021-32613-2834f321",
"signature_type": "Line",
"signature_version": "v1"
},
{
"source": "https://github.com/radareorg/radare2/commit/5e16e2d1c9fe245e4c17005d779fde91ec0b9c05",
"target": {
"function": "get_none_object",
"file": "libr/bin/format/pyc/marshal.c"
},
"digest": {
"function_hash": "281144442903635776283408469084151380870",
"length": 228.0
},
"deprecated": false,
"id": "CVE-2021-32613-89e7b878",
"signature_type": "Function",
"signature_version": "v1"
},
{
"source": "https://github.com/radareorg/radare2/commit/5e16e2d1c9fe245e4c17005d779fde91ec0b9c05",
"target": {
"file": "libr/bin/format/pyc/marshal.c"
},
"digest": {
"line_hashes": [
"293727422535202617895383407783017198569",
"325426534639164205903082921648749687711",
"228831602891691957477592427643617201977",
"224186186095923557659101101390381017579",
"212850913520644578786064218748185165524",
"172004653938665698361432276404790548809",
"26425263749308728204585716171309190508",
"149829655951370627201221230733046478701",
"246419025862705036512837914482105705955",
"228127056506232150828101904703011610912"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2021-32613-e60a11fd",
"signature_type": "Line",
"signature_version": "v1"
},
{
"source": "https://github.com/radareorg/radare2/commit/5e16e2d1c9fe245e4c17005d779fde91ec0b9c05",
"target": {
"function": "get_object",
"file": "libr/bin/format/pyc/marshal.c"
},
"digest": {
"function_hash": "152887779541464158850990740854948468430",
"length": 2432.0
},
"deprecated": false,
"id": "CVE-2021-32613-f6dc3e9a",
"signature_type": "Function",
"signature_version": "v1"
}
]