CVE-2026-22780
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/02/2026
Last modified:
02/02/2026
Description
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Prior to 0.8.2, a heap overflow can be exploited when a malicious mach0 file, having bogus entries for the dyld chained segments, is parsed by rizin. This vulnerability is fixed in 0.8.2.
Impact
Base Score 3.x
4.40
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/rizinorg/rizin/blob/6dd0dba9ff4dc706f549d0cdcd93856b49e59aa0/librz/bin/format/mach0/mach0_chained_fixups.c#L200
- https://github.com/rizinorg/rizin/commit/41ea75d5b07d9b41b27ae80675cdda65f1b1c989
- https://github.com/rizinorg/rizin/issues/5768
- https://github.com/rizinorg/rizin/pull/5770
- https://github.com/rizinorg/rizin/releases/tag/v0.8.2
- https://github.com/rizinorg/rizin/security/advisories/GHSA-f3v7-xhmj-9cjj



