Radare2: Stack-use-after-return in check_buffer
A stack-use-after-return vulnerability has been identified in the check_buffer function of radare2, as reported by OSS-Fuzz. This issue involves reading memory after the stack frame has been returned, which can lead to undefined behavior or potential security risks. Multiple specific versions of radare2 are affected. There is no CVSS score or vendor advisory available to confirm patch status or exploitation in the wild.
AI Analysis
Technical Summary
The vulnerability is a stack-use-after-return read detected in the check_buffer function within radare2, as reported by OSS-Fuzz (OSV-2022-993). The crash occurs during the execution of check_buffer, r_bin_get_binplugin_by_buffer, and r_bin_file_new_from_buffer functions. This indicates that the software accesses stack memory after the function has returned, which is a form of use-after-return bug. The affected versions include specific releases from 5.8.0 through 6.2.0. No patch or official fix information is provided in the available data.
Potential Impact
The stack-use-after-return vulnerability could lead to undefined behavior, including potential memory corruption or information disclosure. However, no known exploits in the wild have been reported. The absence of a CVSS score and detailed impact analysis limits precise severity assessment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should monitor radare2 updates and consider avoiding affected versions if possible.
Radare2: Stack-use-after-return in check_buffer
Description
A stack-use-after-return vulnerability has been identified in the check_buffer function of radare2, as reported by OSS-Fuzz. This issue involves reading memory after the stack frame has been returned, which can lead to undefined behavior or potential security risks. Multiple specific versions of radare2 are affected. There is no CVSS score or vendor advisory available to confirm patch status or exploitation in the wild.
Affected software
pkg:generic/radare2Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability is a stack-use-after-return read detected in the check_buffer function within radare2, as reported by OSS-Fuzz (OSV-2022-993). The crash occurs during the execution of check_buffer, r_bin_get_binplugin_by_buffer, and r_bin_file_new_from_buffer functions. This indicates that the software accesses stack memory after the function has returned, which is a form of use-after-return bug. The affected versions include specific releases from 5.8.0 through 6.2.0. No patch or official fix information is provided in the available data.
Potential Impact
The stack-use-after-return vulnerability could lead to undefined behavior, including potential memory corruption or information disclosure. However, no known exploits in the wild have been reported. The absence of a CVSS score and detailed impact analysis limits precise severity assessment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should monitor radare2 updates and consider avoiding affected versions if possible.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- OSV-2022-993
- Osv Schema Version
- 1.3.0
- Aliases
- []
- Ecosystems
- ["OSS-Fuzz"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7891debf8831d539c87a15
Added to database: 08/09/2026, 14:42:38 UTC
Last enriched: 08/09/2026, 14:53:31 UTC
Last updated: 08/09/2026, 15:33:04 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.