CVEFinder.io

CVE-2026-8696

⚠️ high
🔍 Scan for this CVE
Summary

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed thread information responses. Attackers can trigger the vulnerability by causing qsThreadInfo to fail after qfThreadInfo successfully allocates RDebugPid structures, resulting in double-free memory corruption when the error path attempts to clean up the list.

CVSS Score
7.5
High
EPSS Score
0.4
Exploit Probability
Published Date
2026-05-15
First Seen: 2026-05-17
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 69.0% of all 328,009 vulnerabilities in our database.

#101,817
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: May 19, 2026
🔍 Exploitation Status
Poc
Proof-of-concept available
⚙️ Automatable
YES
Can be exploited automatically
💥 Technical Impact
Partial
Limited system impact
🏆 Discovered By
Saad Elharaj
SSVC data provided by CISA
Last Modified 2026-05-19
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Vector 4.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 3

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-8695 ⚠️ high 7.5 0.4 radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers t... 2026-05-15
CVE-2026-6940 ⚠️ high 7.1 0.0 radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recurs... 2026-04-23
CVE-2026-6941 🔶 medium 6.6 0.0 radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to re... 2026-04-23
CVE-2026-40517 ⚠️ high 7.8 0.0 radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows... 2026-04-22
CVE-2026-40527 ⚠️ high 7.8 0.1 radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ... 2026-04-17
CVE-2026-40499 ⚠️ high 7.8 0.0 radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function tha... 2026-04-15
These CVEs affect the same products