CVEFinder.io

CVE-2026-8696

âš ī¸ high
🔍 Scan for this CVE
Summary

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed thread information responses. Attackers can trigger the vulnerability by causing qsThreadInfo to fail after qfThreadInfo successfully allocates RDebugPid structures, resulting in double-free memory corruption when the error path attempts to clean up the list.

CVSS Score
7.5
High
EPSS Score
0.4
Exploit Probability
Published Date
2026-05-15
First Seen: 2026-05-17
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 67.8% of all 356,676 vulnerabilities in our database.

#114,677
Above average severity
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: May 19, 2026
🔍 Exploitation Status
Poc
Proof-of-concept available
âš™ī¸ Automatable
YES
Can be exploited automatically
đŸ’Ĩ Technical Impact
Partial
Limited system impact
🏆 Discovered By
Saad Elharaj
SSVC data provided by CISA
Last Modified 2026-05-19
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Vector 4.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 1

🔗 References 3

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-14786 â„šī¸ low 3.3 0.1 A security flaw has been discovered in radareorg radare2 up to 6.1.6. This impacts the function r_str_word_get0set of th... 2026-07-06
CVE-2026-14787 â„šī¸ low 3.3 0.1 A weakness has been identified in radareorg radare2 up to 6.1.6. Affected is the function cmd_print in the library libr/... 2026-07-06
CVE-2026-14788 â„šī¸ low 3.3 0.1 A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the funct... 2026-07-06
CVE-2026-14789 â„šī¸ low 3.3 0.2 A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of t... 2026-07-06
CVE-2026-14757 đŸ”ļ medium 5.3 0.1 A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file l... 2026-07-05
CVE-2026-14758 â„šī¸ low 3.3 0.1 A vulnerability was identified in radareorg radare2 up to 6.1.6. This vulnerability affects the function cmd_anal_opcode... 2026-07-05
These CVEs affect the same products