Rizin is a UNIX-like reverse engineering framework and command-line toolset. In versions up to and including 0.3.1 there is a heap-based out of bounds write in parse_die() when reversing an AMD64 ELF binary with DWARF debug info. When a malicious AMD64 ELF binary is opened by a victim user, Rizin may crash or execute unintended actions. No workaround are known and users are advised to upgrade.
{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "0.3.1"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:rizin:rizin:*:*:*:*:*:*:*:*"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43814.json"
[
{
"target": {
"function": "init_die",
"file": "librz/bin/dwarf.c"
},
"deprecated": false,
"source": "https://github.com/rizinorg/rizin/commit/aa6917772d2f32e5a7daab25a46c72df0b5ea406",
"id": "CVE-2021-43814-07deded8",
"signature_version": "v1",
"digest": {
"length": 318.0,
"function_hash": "184946763407743022440601383711130511345"
},
"signature_type": "Function"
},
{
"target": {
"file": "librz/bin/dwarf.c"
},
"deprecated": false,
"source": "https://github.com/rizinorg/rizin/commit/aa6917772d2f32e5a7daab25a46c72df0b5ea406",
"id": "CVE-2021-43814-272eb637",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"171946936285818130203829138916687425606",
"155392356072842539040641871064869440824",
"108810878848874356048509395617253116299",
"15985135912317706970131247717054542017",
"105008056566433135516283557564091710069",
"211586272888071465271238932326398938439",
"220652809728302332013342877163635112130",
"208321926003742254237572581827785273579",
"169318641771539373432137790962547172679",
"64206610611324884534206476519567992523",
"80194050254231123193342494689613942651",
"128645928682106217104578686639896713356",
"9670304221076258021105079028600091643",
"232872363258518537691122426263530681166",
"338653745380197531107530713057209491546",
"130882101396445514098435889893925001569",
"222420456810984125243754093713299076856",
"206324330596012986101210398358147096288",
"286242271356782261242154970556816375037",
"58559440571746246767186048242628164209",
"195922458555335183653931091652688068468",
"138040944904516051450037403471016540945",
"92117192771292488363151915803235497222",
"111641847976220110938756438541456333546",
"339128023331091000090433989917573654817"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "parse_die",
"file": "librz/bin/dwarf.c"
},
"deprecated": false,
"source": "https://github.com/rizinorg/rizin/commit/aa6917772d2f32e5a7daab25a46c72df0b5ea406",
"id": "CVE-2021-43814-affc1a39",
"signature_version": "v1",
"digest": {
"length": 1173.0,
"function_hash": "156499722868420146230202167294282105014"
},
"signature_type": "Function"
}
]
"2026-08-07T19:46:59Z"