radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted dataoff and datasize and allowed a final partial record to be processed. The vulnerability is triggered by opening a crafted Mach-O file while the non-default bin.verbose option is enabled. When datasize was not a multiple of data_in_code_entry, the last iteration read beyond the allocated buffer. This can cause a heap out-of-bounds read and possible process termination; no attacker-observable memory disclosure has been demonstrated. This issue is fixed in version 6.2.0.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81884.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81884.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"286160244888699460811464227808019848601",
"60352217793567154767357724837960240255",
"269485997884711083668868891392799686636",
"15399857215165044507756077121116418424",
"217310420395991507177353250734268411680",
"313860942273087068846139082218274064471",
"86316422798747350748280685280969985209",
"304554858293692662214818012905429485845",
"68203620508166344805454201805924569216",
"331862452615461555175131101471736611895",
"217030307842238052689359819444887558206",
"264624757289019215169720187088361158815",
"196021554363270222784429411788803843734",
"230765003810445714447551968187106300202",
"110151303470496903892837858032233667764",
"310382417860840360291950622956039482748",
"53269493975263036937840712408954927514"
],
"threshold": 0.9
},
"id": "CVE-2026-81884-7d2b11eb",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/radareorg/radare2/commit/a73de09fea7516f65c14917d66113316ec7e7d6e",
"target": {
"file": "libr/bin/format/mach0/mach0.c"
}
}
]
"2026-09-24T08:26:11Z"