CVE-2024-29645

Source
https://cve.org/CVERecord?id=CVE-2024-29645
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-29645.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-29645
Downstream
Related
Published
2024-12-02T00:00:00Z
Modified
2026-07-16T00:03:39.387539Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29645.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/radareorg/radare2

Affected ranges

Type
GIT
Repo
https://github.com/radareorg/radare2
Events
Database specific
{
    "cpe": "cpe:2.3:a:radare:radare2:5.8.8:*:*:*:*:*:*:*",
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "5.8.8"
        },
        {
            "last_affected": "5.8.8"
        }
    ]
}

Affected versions

5.*
5.8.8

Database specific

vanir_signatures
[
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "33435570322654944071731113002903915555",
                "245073513219679127995455990445233211178",
                "21761884000694845879578159062724773603",
                "291529486545459762773070714824903876874",
                "127103925894420967225577159290088205084",
                "249593335712890702076303022958561411189",
                "1758610508061019667833980366903960844",
                "231772665964479650804363316448549251863",
                "233748673008388362196052551723409394639",
                "250333135175176172488689916301147530327",
                "171665585604210462846165350112580264965",
                "258196392282236291777640060989125548378",
                "337919552740785433514115414092768613449",
                "269006887821942665165848067854022667649",
                "158393646236167971911388210189270486882",
                "4031036519472616573958429962822075452",
                "295353147238651772346657765235041142307",
                "253389027935223966299199010134337828043",
                "176956982209746041867051038606777429304",
                "290591691589904513403898015395204605035",
                "259139251199822529676503554233400010688",
                "198482572048194978744401739788710370520",
                "160103203560112078492527748129059580928",
                "147057317968086428115679185706868693251",
                "219354072709614014385930657095419188706",
                "338356836678832910398898739290157526197",
                "323925193701978155341854879245361426192",
                "323469726076888676260208634455071535214",
                "158765850954711826728630842704041149070",
                "12059753624352920590225375608279548176",
                "173931485492044464542052044769291003559"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/radareorg/radare2/commit/72bf3a486fa851797aa21887a40ba0e3d3a6d620",
        "signature_type": "Line",
        "target": {
            "file": "libr/bin/dwarf.c"
        },
        "id": "CVE-2024-29645-148de5f4",
        "deprecated": false
    },
    {
        "digest": {
            "length": 1454.0,
            "function_hash": "109577763466092032469651679624700479732"
        },
        "signature_version": "v1",
        "source": "https://github.com/radareorg/radare2/commit/72bf3a486fa851797aa21887a40ba0e3d3a6d620",
        "signature_type": "Function",
        "target": {
            "function": "parse_die",
            "file": "libr/bin/dwarf.c"
        },
        "id": "CVE-2024-29645-88be7a91",
        "deprecated": false
    },
    {
        "digest": {
            "length": 324.0,
            "function_hash": "325941272322752678164597118540279336169"
        },
        "signature_version": "v1",
        "source": "https://github.com/radareorg/radare2/commit/72bf3a486fa851797aa21887a40ba0e3d3a6d620",
        "signature_type": "Function",
        "target": {
            "function": "init_die",
            "file": "libr/bin/dwarf.c"
        },
        "id": "CVE-2024-29645-8b179da2",
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-07-16T00:03:39Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-29645.json"