CVE-2026-14786: Integer Overflow in radareorg radare2
A security flaw has been discovered in radareorg radare2 up to 6.1.6. This impacts the function r_str_word_get0set of the file libr/util/str.c. The manipulation results in integer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is identified as 11ac224c0eb8d57830fccc99e1c1cd8e5d958813. It is best practice to apply a patch to resolve this issue.
AI Analysis
Technical Summary
CVE-2026-14786 is an integer overflow vulnerability affecting radareorg radare2 versions 6.1.0 through 6.1.6. The flaw occurs in the r_str_word_get0set function in libr/util/str.c, where improper handling of integer operations can lead to overflow. Exploitation requires local access and no user interaction. A patch has been identified (commit 11ac224c0eb8d57830fccc99e1c1cd8e5d958813) to fix this issue.
Potential Impact
The integer overflow could potentially lead to unexpected behavior or memory corruption within the affected function. Since exploitation requires local access and no user interaction, the risk is limited to local users with at least low privileges. The CVSS score of 4.8 reflects a medium severity impact.
Mitigation Recommendations
A patch identified by commit 11ac224c0eb8d57830fccc99e1c1cd8e5d958813 is available and should be applied to affected versions 6.1.0 through 6.1.6 of radare2. Applying this patch is the recommended remediation to resolve the vulnerability.
CVE-2026-14786: Integer Overflow in radareorg radare2
Description
A security flaw has been discovered in radareorg radare2 up to 6.1.6. This impacts the function r_str_word_get0set of the file libr/util/str.c. The manipulation results in integer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is identified as 11ac224c0eb8d57830fccc99e1c1cd8e5d958813. It is best practice to apply a patch to resolve this issue.
CVSS v4.0
Score 4.8medium
Affected software
pkg:github/radareorg/radare2cpe:2.3:a:radareorg:radare2:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-14786 is an integer overflow vulnerability affecting radareorg radare2 versions 6.1.0 through 6.1.6. The flaw occurs in the r_str_word_get0set function in libr/util/str.c, where improper handling of integer operations can lead to overflow. Exploitation requires local access and no user interaction. A patch has been identified (commit 11ac224c0eb8d57830fccc99e1c1cd8e5d958813) to fix this issue.
Potential Impact
The integer overflow could potentially lead to unexpected behavior or memory corruption within the affected function. Since exploitation requires local access and no user interaction, the risk is limited to local users with at least low privileges. The CVSS score of 4.8 reflects a medium severity impact.
Mitigation Recommendations
A patch identified by commit 11ac224c0eb8d57830fccc99e1c1cd8e5d958813 is available and should be applied to affected versions 6.1.0 through 6.1.6 of radare2. Applying this patch is the recommended remediation to resolve the vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-07-05T16:03:14.292Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a4b033127e9c797194f587c
Added to database: 07/06/2026, 01:21:53 UTC
Last enriched: 07/06/2026, 21:24:16 UTC
Last updated: 08/19/2026, 22:52:10 UTC
Views: 120
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.