CVE-2025-63744

Source
https://cve.org/CVERecord?id=CVE-2025-63744
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-63744.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-63744
Downstream
Published
2025-11-14T21:15:44.933Z
Modified
2026-04-12T18:40:05.087081Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
Summary
[none]
Details

A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a segmentation fault and crash the program.

References

Affected packages

Git / github.com/radareorg/radare2

Affected ranges

Type
GIT
Repo
https://github.com/radareorg/radare2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.4-termux4
0.10.5
0.10.6
0.8.6
0.8.8
0.9
0.9.2
0.9.4
0.9.6
0.9.7
0.9.8
0.9.8-rc1
0.9.8-rc2
0.9.8-rc3
0.9.8-rc4
0.9.9
1.*
1.0
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.2.0-git
1.3.0
1.3.0-git
1.4.0
1.5.0
1.6.0
2.*
2.0.0
2.0.1
2.1.0
2.2.0
2.4.0
2.5.0
2.6.0
2.6.9
2.7.0
2.8.0
2.9.0
3.*
3.0.0
3.0.1
3.1.0
3.1.1
3.1.2
3.1.3
3.2.0
3.2.1
3.3.0
3.4.0
3.4.1
3.5.0
3.5.1
3.6.0
3.7.0
3.7.1
3.8.0
3.9.0
4.*
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.4.0
4.5.1
5.*
5.0.0
5.1.0
5.1.1
5.2.0
5.2.1
5.3.0
5.3.1
5.4.0
5.4.0-git
5.4.2
5.5.0
5.5.2
5.5.4
5.6.0
5.6.2
5.6.4
5.6.6
5.6.8
5.7.0
5.7.2
5.7.4
5.7.6
5.7.8
5.8.0
5.8.2
5.8.4
5.8.6
5.8.8
5.9.0
5.9.2
5.9.4
5.9.6
5.9.8
6.*
6.0.0
6.0.2
6.0.4
Other
Continuous-Windows
continuous
radare2-windows-nightly
termux
wip
release-5.*
release-5.0.0

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "6.0.5"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-63744.json"
vanir_signatures_modified
"2026-04-12T18:40:05Z"
vanir_signatures
[
    {
        "digest": {
            "length": 896.0,
            "function_hash": "280686398059582809230371115181811383975"
        },
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2025-63744-37db9064",
        "signature_version": "v1",
        "source": "https://github.com/radareorg/radare2/commit/e37e15d10fd8a19c3e57b3d7735a2cfe0082ec79",
        "target": {
            "function": "load",
            "file": "libr/bin/p/bin_dyldcache.c"
        }
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "92165652376797098845581650203662477337",
                "136658990366017164162942350455965994111",
                "237845404260024669036033568911038436509"
            ]
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2025-63744-ea47c45c",
        "signature_version": "v1",
        "source": "https://github.com/radareorg/radare2/commit/e37e15d10fd8a19c3e57b3d7735a2cfe0082ec79",
        "target": {
            "file": "libr/bin/format/ne/ne.c"
        }
    },
    {
        "digest": {
            "length": 349.0,
            "function_hash": "212712312903010031125822073674075562206"
        },
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2025-63744-f163c232",
        "signature_version": "v1",
        "source": "https://github.com/radareorg/radare2/commit/e37e15d10fd8a19c3e57b3d7735a2cfe0082ec79",
        "target": {
            "function": "__get_target_os",
            "file": "libr/bin/format/ne/ne.c"
        }
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "20729632394535854247765476967555511691",
                "181566176290777898915310946553781309329",
                "158594174275866071419317411297673972025",
                "61732863325773233763159170638624266488"
            ]
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2025-63744-f7e0cdab",
        "signature_version": "v1",
        "source": "https://github.com/radareorg/radare2/commit/e37e15d10fd8a19c3e57b3d7735a2cfe0082ec79",
        "target": {
            "file": "libr/bin/p/bin_dyldcache.c"
        }
    }
]