CVE-2021-43814

Source
https://cve.org/CVERecord?id=CVE-2021-43814
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43814.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-43814
Aliases
  • GHSA-hqqp-vjcm-mw8r
Published
2021-12-13T20:15:07Z
Modified
2026-08-07T19:46:59Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Rizin is a UNIX-like reverse engineering framework and command-line toolset. In versions up to and including 0.3.1 there is a heap-based out of bounds write in parse_die() when reversing an AMD64 ELF binary with DWARF debug info. When a malicious AMD64 ELF binary is opened by a victim user, Rizin may crash or execute unintended actions. No workaround are known and users are advised to upgrade.

References

Affected packages

Git / github.com/rizinorg/rizin

Affected ranges

Type
GIT
Repo
https://github.com/rizinorg/rizin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:rizin:rizin:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "0.3.1"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.1.0
v0.*
v0.1.0
v0.1.1
v0.1.2
v0.2.0
v0.2.1
v0.3.0
v0.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43814.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "184946763407743022440601383711130511345",
            "length":  318
        },
        "id":  "CVE-2021-43814-07deded8",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/rizinorg/rizin/commit/aa6917772d2f32e5a7daab25a46c72df0b5ea406",
        "target":  {
            "file":  "librz/bin/dwarf.c",
            "function":  "init_die"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "171946936285818130203829138916687425606",
                "155392356072842539040641871064869440824",
                "108810878848874356048509395617253116299",
                "15985135912317706970131247717054542017",
                "105008056566433135516283557564091710069",
                "211586272888071465271238932326398938439",
                "220652809728302332013342877163635112130",
                "208321926003742254237572581827785273579",
                "169318641771539373432137790962547172679",
                "64206610611324884534206476519567992523",
                "80194050254231123193342494689613942651",
                "128645928682106217104578686639896713356",
                "9670304221076258021105079028600091643",
                "232872363258518537691122426263530681166",
                "338653745380197531107530713057209491546",
                "130882101396445514098435889893925001569",
                "222420456810984125243754093713299076856",
                "206324330596012986101210398358147096288",
                "286242271356782261242154970556816375037",
                "58559440571746246767186048242628164209",
                "195922458555335183653931091652688068468",
                "138040944904516051450037403471016540945",
                "92117192771292488363151915803235497222",
                "111641847976220110938756438541456333546",
                "339128023331091000090433989917573654817"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2021-43814-272eb637",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/rizinorg/rizin/commit/aa6917772d2f32e5a7daab25a46c72df0b5ea406",
        "target":  {
            "file":  "librz/bin/dwarf.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "156499722868420146230202167294282105014",
            "length":  1173
        },
        "id":  "CVE-2021-43814-affc1a39",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/rizinorg/rizin/commit/aa6917772d2f32e5a7daab25a46c72df0b5ea406",
        "target":  {
            "file":  "librz/bin/dwarf.c",
            "function":  "parse_die"
        }
    }
]
vanir_signatures_modified
"2026-08-07T19:46:59Z"