CVE-2026-81886: CWE-770: Allocation of Resources Without Limits or Throttling in radareorg radare2
CVE-2026-81886 is a resource allocation vulnerability in radare2 prior to version 6.2.0. The Windows 64-bit crash-dump dmp64 parser improperly uses an input-controlled PageCount as the bound for memory allocation loops without validating it against the dump size. This can lead to excessive memory consumption and processing time, causing a denial of service. The issue is fixed in radare2 version 6.2.0.
AI Analysis
Technical Summary
The vulnerability in radare2's Windows 64-bit crash-dump dmp64 parser arises because the parser uses an input-controlled physical-memory-run PageCount directly as the loop bound for per-page allocations. When a crafted full-memory Windows crash dump with a small size but a large PageCount is opened, the parser repeatedly allocates and appends page descriptors without validating the count against the actual dump size. This unchecked allocation can cause excessive memory consumption and processing time, resulting in a denial of service condition. The vulnerability is addressed and fixed in radare2 version 6.2.0.
Potential Impact
An attacker can cause a denial of service by supplying a crafted Windows crash dump that triggers excessive memory allocation and CPU consumption in the vulnerable parser. There is no impact on confidentiality or integrity reported. The impact is limited to availability degradation due to resource exhaustion.
Mitigation Recommendations
Upgrade radare2 to version 6.2.0 or later, where this vulnerability is fixed. No other mitigations are specified or required.
CVE-2026-81886: CWE-770: Allocation of Resources Without Limits or Throttling in radareorg radare2
Description
CVE-2026-81886 is a resource allocation vulnerability in radare2 prior to version 6.2.0. The Windows 64-bit crash-dump dmp64 parser improperly uses an input-controlled PageCount as the bound for memory allocation loops without validating it against the dump size. This can lead to excessive memory consumption and processing time, causing a denial of service. The issue is fixed in radare2 version 6.2.0.
CVSS v3.1
Score 5.5medium
Affected software
radareorg
radare2
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in radare2's Windows 64-bit crash-dump dmp64 parser arises because the parser uses an input-controlled physical-memory-run PageCount directly as the loop bound for per-page allocations. When a crafted full-memory Windows crash dump with a small size but a large PageCount is opened, the parser repeatedly allocates and appends page descriptors without validating the count against the actual dump size. This unchecked allocation can cause excessive memory consumption and processing time, resulting in a denial of service condition. The vulnerability is addressed and fixed in radare2 version 6.2.0.
Potential Impact
An attacker can cause a denial of service by supplying a crafted Windows crash dump that triggers excessive memory allocation and CPU consumption in the vulnerable parser. There is no impact on confidentiality or integrity reported. The impact is limited to availability degradation due to resource exhaustion.
Mitigation Recommendations
Upgrade radare2 to version 6.2.0 or later, where this vulnerability is fixed. No other mitigations are specified or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-27T17:48:42.122Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab29c3cf7a7c54106580d6a
Added to database: 09/22/2026, 15:18:20 UTC
Last enriched: 09/22/2026, 15:32:37 UTC
Last updated: 09/22/2026, 15:51:19 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.