CVE-2026-81886Medium· 5.5▾ Sunlitradare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 parser used an input-controlled physical-memory-run …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 parser used an input-controlled physical-memory-run PageCount directly as the bound of a per-page allocation loop. The vulnerability is triggered by opening a small crafted full-memory Windows crash dump. The parser repeatedly allocated and appended page descriptors without validating the count against the dump size. This can cause denial of service through excessive memory consumption and processing time. This issue is fixed in version 6.2.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-81885Medium· 5.5radare2 is a UNIX-like reverse engineering framework and command-line toolset
CVE-2026-81881Low· 3.3radare2 is a UNIX-like reverse engineering framework and command-line toolset
CVE-2026-81878Medium· 5.5radare2 is a UNIX-like reverse engineering framework and command-line toolset
CVE-2026-81880Medium· 5.5radare2 is a UNIX-like reverse engineering framework and command-line toolset
CVE-2026-81883Low· 3.3radare2 is a UNIX-like reverse engineering framework and command-line toolset
CVE-2026-81882Low· 3.3radare2 is a UNIX-like reverse engineering framework and command-line toolset