← back
CVE-2022-0139highCWE-416

Use After Free in radareorg/radare2

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.1epss 1.2%
exploitation probability
1.2%top 34% of all CVEs
observed exploitation
nono source reports it
In short

A memory error in radare2 allows an attacker to use data that has already been freed, potentially crashing the application or executing arbitrary code. This happens when the software tries to access memory locations that were previously deallocated.

Technical detail

Use-after-free vulnerability in radare2 prior to version 5.6.0 (CWE-416) allows an attacker to reference freed memory during program execution, potentially leading to information disclosure, denial of service, or code execution depending on the memory layout and exploitation context.

Summary generated and translated by AI from the official description.
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L