Rizin is a UNIX-like reverse engineering framework and command-line toolset. Prior to 0.8.2, a heap overflow can be exploited when a malicious mach0 file, having bogus entries for the dyld chained segments, is parsed by rizin. This vulnerability is fixed in 0.8.2.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22780.json",
"cwe_ids": [
"CWE-770"
],
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:rizin:rizin:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.8.2"
}
]
}
[
{
"id": "CVE-2026-22780-f2e31720",
"target": {
"file": "librz/bin/format/mach0/mach0_chained_fixups.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"127417068885150346941144592067211720198",
"83376431877593269289884463554919647399",
"164863739243027732308007354381640815276",
"170432141134756002464069466926881988139"
]
},
"signature_version": "v1",
"source": "https://github.com/rizinorg/rizin/commit/41ea75d5b07d9b41b27ae80675cdda65f1b1c989",
"signature_type": "Line"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22780.json"
"2026-08-12T15:32:51Z"