A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function rbinjavainnerclassesattrcalc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The patch is named cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87. To fix this issue, it is recommended to deploy a patch.
{
"cwe_ids": [
"CWE-119",
"CWE-122"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14759.json",
"cna_assigner": "VulDB",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "6.1.1"
},
{
"last_affected": "6.1.1"
},
{
"introduced": "6.1.3"
},
{
"last_affected": "6.1.3"
},
{
"introduced": "6.1.5"
},
{
"last_affected": "6.1.5"
}
],
"source": "AFFECTED_FIELD"
}
]
}"2026-08-12T15:31:25Z"
[
{
"id": "CVE-2026-14759-32d7950c",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 1151.0,
"function_hash": "123875560907514860140498792381531283046"
},
"source": "https://github.com/radareorg/radare2/commit/cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87",
"target": {
"function": "r_bin_java_line_number_table_attr_new",
"file": "shlr/java/class.c"
}
},
{
"id": "CVE-2026-14759-fb559299",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"15354281235802217529839225372620832648",
"122392191489199256582368427710233929325",
"173970248630843022324208110650995519056",
"18364852740018612077543003314082820588"
]
},
"source": "https://github.com/radareorg/radare2/commit/cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87",
"target": {
"file": "shlr/java/class.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14759.json"