CVE-2026-45613

Source
https://cve.org/CVERecord?id=CVE-2026-45613
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45613.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45613
Aliases
  • GHSA-wprr-wrcw-mw6v
Downstream
Published
2026-05-29T19:07:49Z
Modified
2026-08-12T16:25:18Z
Severity
  • 3.3 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Rizin: Heap-buffer-overflow in OMF parser
Details

Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a heap-buffer-overflow in librz/bin/format/omf/omf.c. This vulnerability is fixed by commit e6d0937c8a083e23ed76ccfb9f631cdc50c7af47.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-125"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45613.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "e6d0937c8a083e23ed76ccfb9f631cdc50c7af47"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/rizinorg/rizin

Affected ranges

Type
GIT
Repo
https://github.com/rizinorg/rizin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

v0.*
v0.7.0
v0.7.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45613.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "210049910552648900150786063194314128354",
                "174464913411539280396168961121618407710",
                "18700722075327673334814371630446568247",
                "178796751734753272423636565130591010621",
                "222021053054077501630309516858136024546",
                "173624096090581988881338967241991130626",
                "111795943513890264057751968695755417174",
                "274593937123597495633331055849228765673",
                "258886527492765735155739381129967050776"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-45613-80e1add9",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/rizinorg/rizin/commit/e6d0937c8a083e23ed76ccfb9f631cdc50c7af47",
        "target": {
            "file": "librz/bin/format/omf/omf.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "33904963292820360973760364377944707188",
            "length": 834
        },
        "id": "CVE-2026-45613-e59cb86b",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/rizinorg/rizin/commit/e6d0937c8a083e23ed76ccfb9f631cdc50c7af47",
        "target": {
            "file": "librz/bin/format/omf/omf.c",
            "function": "rz_bin_omf_get_entry"
        }
    }
]
vanir_signatures_modified
"2026-08-12T16:25:18Z"