CVE-2021-43814

Source
https://cve.org/CVERecord?id=CVE-2021-43814
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43814.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-43814
Aliases
  • GHSA-hqqp-vjcm-mw8r
Published
2021-12-13T20:15:07.640Z
Modified
2026-08-07T19:46:59.201170Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Rizin is a UNIX-like reverse engineering framework and command-line toolset. In versions up to and including 0.3.1 there is a heap-based out of bounds write in parse_die() when reversing an AMD64 ELF binary with DWARF debug info. When a malicious AMD64 ELF binary is opened by a victim user, Rizin may crash or execute unintended actions. No workaround are known and users are advised to upgrade.

References

Affected packages

Git / github.com/rizinorg/rizin

Affected ranges

Type
GIT
Repo
https://github.com/rizinorg/rizin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.3.1"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:rizin:rizin:*:*:*:*:*:*:*:*"
}

Affected versions

0.*
0.1.0
v0.*
v0.1.0
v0.1.1
v0.1.2
v0.2.0
v0.2.1
v0.3.0
v0.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43814.json"
vanir_signatures
[
    {
        "target": {
            "function": "init_die",
            "file": "librz/bin/dwarf.c"
        },
        "deprecated": false,
        "source": "https://github.com/rizinorg/rizin/commit/aa6917772d2f32e5a7daab25a46c72df0b5ea406",
        "id": "CVE-2021-43814-07deded8",
        "signature_version": "v1",
        "digest": {
            "length": 318.0,
            "function_hash": "184946763407743022440601383711130511345"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "librz/bin/dwarf.c"
        },
        "deprecated": false,
        "source": "https://github.com/rizinorg/rizin/commit/aa6917772d2f32e5a7daab25a46c72df0b5ea406",
        "id": "CVE-2021-43814-272eb637",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "171946936285818130203829138916687425606",
                "155392356072842539040641871064869440824",
                "108810878848874356048509395617253116299",
                "15985135912317706970131247717054542017",
                "105008056566433135516283557564091710069",
                "211586272888071465271238932326398938439",
                "220652809728302332013342877163635112130",
                "208321926003742254237572581827785273579",
                "169318641771539373432137790962547172679",
                "64206610611324884534206476519567992523",
                "80194050254231123193342494689613942651",
                "128645928682106217104578686639896713356",
                "9670304221076258021105079028600091643",
                "232872363258518537691122426263530681166",
                "338653745380197531107530713057209491546",
                "130882101396445514098435889893925001569",
                "222420456810984125243754093713299076856",
                "206324330596012986101210398358147096288",
                "286242271356782261242154970556816375037",
                "58559440571746246767186048242628164209",
                "195922458555335183653931091652688068468",
                "138040944904516051450037403471016540945",
                "92117192771292488363151915803235497222",
                "111641847976220110938756438541456333546",
                "339128023331091000090433989917573654817"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "parse_die",
            "file": "librz/bin/dwarf.c"
        },
        "deprecated": false,
        "source": "https://github.com/rizinorg/rizin/commit/aa6917772d2f32e5a7daab25a46c72df0b5ea406",
        "id": "CVE-2021-43814-affc1a39",
        "signature_version": "v1",
        "digest": {
            "length": 1173.0,
            "function_hash": "156499722868420146230202167294282105014"
        },
        "signature_type": "Function"
    }
]
vanir_signatures_modified
"2026-08-07T19:46:59Z"