rizin before v0.6.3 is vulnerable to Buffer Overflow via createcachebins, readcacheaccel, and rzdyldcachenew_buf functions in librz/bin/format/mach0/dyldcache.c.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/31xxx/CVE-2024-31670.json"
}{
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:rizin:rizin:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.6.3"
}
]
}"2026-08-08T09:47:34Z"
[
{
"target": {
"function": "rz_dyldcache_new_buf",
"file": "librz/bin/format/mach0/dyldcache.c"
},
"digest": {
"length": 609.0,
"function_hash": "58262868138063189452359665451193502768"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2024-31670-832ca766",
"source": "https://github.com/rizinorg/rizin/commit/75bac3088b2ec173e22d4be9d525ceacc987cf02"
},
{
"target": {
"function": "read_cache_accel",
"file": "librz/bin/format/mach0/dyldcache.c"
},
"digest": {
"length": 841.0,
"function_hash": "314028342897745400195669508889791448972"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2024-31670-8873be87",
"source": "https://github.com/rizinorg/rizin/commit/75bac3088b2ec173e22d4be9d525ceacc987cf02"
},
{
"target": {
"function": "create_cache_bins",
"file": "librz/bin/format/mach0/dyldcache.c"
},
"digest": {
"length": 3758.0,
"function_hash": "256695099205391455690157599532580480837"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2024-31670-a6a5bca6",
"source": "https://github.com/rizinorg/rizin/commit/75bac3088b2ec173e22d4be9d525ceacc987cf02"
},
{
"target": {
"file": "librz/bin/format/mach0/dyldcache.c"
},
"digest": {
"line_hashes": [
"260169637974387149379128062662532549875",
"313930794252959565929684113640467952005",
"282447215717882830671433862531634236563",
"100655825308428834543970681936620606390",
"18772926460710974742276859374737556714",
"124943200428514757914050311129412486563",
"263782245906525260577087265545251738762",
"234285395805901954516181059530364893616",
"271181938578679421927994831413655718277",
"123759436810096849085359356080358122409",
"125644714855743244835571021889880452766",
"176567526503691916335638984576910704820",
"120625257675922998548265677636227844417",
"20531873999069567496068474870587776327",
"31540796248795974536599264825095925742",
"293266930025055816019316443172094513387",
"289570638440673542928992983621587834347",
"154583043707244852992864084022024124709",
"120234637199861574248704031023554497610",
"13096946032531602271589297050430756586"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2024-31670-bce595a4",
"source": "https://github.com/rizinorg/rizin/commit/75bac3088b2ec173e22d4be9d525ceacc987cf02"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-31670.json"