radare2 6.1.5 contains a use-after-free vulnerability in the gdbrthreadslist() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability through GDB remote debugging to cause a denial of service or potentially achieve code execution by manipulating thread list processing.
{
"cwe_ids": [
"CWE-416"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8695.json",
"cna_assigner": "VulnCheck",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "6.1.5"
},
{
"last_affected": "6.1.5"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"cpe": "cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "6.1.4"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"2026-08-12T16:09:27Z"
[
{
"id": "CVE-2026-8695-70973ae5",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"2642052920581848624711627094758784712",
"298746145323710817571145825272166239688",
"302718793558120408020522354935904811081",
"24434517642606170844450134190884804256",
"23774614703414143850685639556053030212",
"296191418765010999778435458980558993390",
"284198222350527817184538641400580681722",
"247840309004918720137644774753409230561",
"196562980804278100100706086502158942623",
"298746145323710817571145825272166239688",
"302718793558120408020522354935904811081",
"24434517642606170844450134190884804256",
"23774614703414143850685639556053030212",
"296191418765010999778435458980558993390",
"284198222350527817184538641400580681722",
"247840309004918720137644774753409230561"
]
},
"source": "https://github.com/radareorg/radare2/commit/c213ad6894a1eb9086ac8bf5fae35757e9e1683c",
"target": {
"file": "shlr/gdb/src/gdbclient/core.c"
}
},
{
"id": "CVE-2026-8695-c296df6d",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 2012.0,
"function_hash": "317445950644508715972161712361566372156"
},
"source": "https://github.com/radareorg/radare2/commit/c213ad6894a1eb9086ac8bf5fae35757e9e1683c",
"target": {
"function": "gdbr_pids_list",
"file": "shlr/gdb/src/gdbclient/core.c"
}
},
{
"id": "CVE-2026-8695-c427e157",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 1929.0,
"function_hash": "129840934556160151434869769218248091436"
},
"source": "https://github.com/radareorg/radare2/commit/c213ad6894a1eb9086ac8bf5fae35757e9e1683c",
"target": {
"function": "gdbr_threads_list",
"file": "shlr/gdb/src/gdbclient/core.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8695.json"