CVE-2026-14789
Severity CVSS v4.0:
LOW
Type:
CWE-119
Buffer Errors
Publication date:
06/07/2026
Last modified:
09/07/2026
Description
A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of the file libr/bin/format/mdmp/mdmp.c of the component Memory64ListStream Parser. Performing a manipulation results in stack-based buffer overflow. The attack requires a local approach. The exploit is now public and may be used. The patch is named 175d4addb68981331c85b10681c2161c38fb5762. It is suggested to install a patch to address this issue.
Impact
Base Score 4.0
1.90
Severity 4.0
LOW
Base Score 3.x
3.30
Severity 3.x
LOW
Base Score 2.0
1.70
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:* | 6.1.0 (including) | 6.1.6 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/mengzhisuoliu/radare2/commit/175d4addb68981331c85b10681c2161c38fb5762
- https://github.com/radareorg/radare2/
- https://github.com/radareorg/radare2/issues/26051
- https://vuldb.com/cve/CVE-2026-14789
- https://vuldb.com/submit/850389
- https://vuldb.com/vuln/376378
- https://vuldb.com/vuln/376378/cti



