openSUSE-SU-2026:21988-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21988-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21988-1
Upstream
CVE (20)
Related
Published
2026-09-25T08:25:52Z
Modified
2026-10-01T18:23:10Z
Summary
Security update for radare2
Details

This update for radare2 fixes the following issues:

Changes in radare2:

  • Update to version 6.2.2:

    • Analysis: new JNI plugin with typed interface tables, arm64 Swift float calling conventions, DWARF prototype linking, jump-table and switch-case fixes
    • Core: fix RAnalOp leaks in disasm/diff/debug loops, aoj memory use, partial-read handling, fp variable recovery
    • Bundle sdb 2.5.2 (upstream pin): rename shlib to libsdb2_5_2
    • Details can be found here: https://github.com/radareorg/radare2/releases/tag/6.2.2
  • Security issues fixed:

    • CVE-2026-81886: Validate dmp64 page counts against dump size (boo#1282346).
    • CVE-2026-81885: Fix infinite loop in the NE fixup parser (boo#1282345).
    • CVE-2026-81884: Validate Mach-O LC_DATA_IN_CODE ranges (boo#1282344).
    • CVE-2026-81883: Fix Lua function parser OOB reads (boo#1282343).
    • CVE-2026-81882: Fix bplist Unicode string conversion (boo#1282342).
    • CVE-2026-81881: Fix Swift Mach-O field metadata bounds check (boo#1282341).
    • CVE-2026-81880: Decode PEF relocs lazily, add more bounds and overflow checks (boo#1282340).
    • CVE-2026-81879: Fix oobread in ELF PN_XNUM phdr count handling (boo#1282339).
    • CVE-2026-81878: Fix heap write overflow in Python loader (boo#1282338).
    • CVE-2026-14788: Denial of Service via use-after-free in r_core_bin_load function (boo#1270453).
    • CVE-2026-14761: Denial of service via integer overflow in string manipulation functions (boo#1270452).
    • CVE-2026-14760: Denial of Service via local use-after-free vulnerability (boo#1270450).
    • CVE-2026-14759: Denial of Service via heap-based buffer overflow (boo#1270449).
    • CVE-2026-14758: Denial of Service via integer overflow in hexpairs parser (boo#1270447).
    • CVE-2026-14757: Integer overflow allows local impact (boo#1270445).
    • CVE-2026-40527: Command injection vulnerability in the afsv/afsvj (boo#1262336).
    • CVE-2026-4174: Missing validation against an upper limit when allocating memory in the Mach-O file parser can lead to excessive resource consumption (boo#1259722).
  • Security issue fixed with the previous release:

    • CVE-2026-41015: Configured on UNIX without SSL, allows command injection via a PDB name to rabin2 (boo#1262190).
    • CVE-2026-40517: Crafted PDB file with newline characters in symbol names can allow to inject arbitrary commands (boo#1262680).
    • CVE-2026-8695: UAFs in the gdb remote protocol ##crash (boo#1265403).
References

Affected packages

openSUSE:Leap 16.0 / radare2

Package

Name
radare2
Purl
pkg:rpm/opensuse/radare2&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.2.2-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "libsdb2_5_2":  "6.2.2-bp160.1.1",
            "radare2":  "6.2.2-bp160.1.1",
            "radare2-devel":  "6.2.2-bp160.1.1",
            "radare2-zsh-completion":  "6.2.2-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21988-1.json"