Bugzilla – Bug 1217386
VUL-0: CVE-2023-47016: radare2: out-of-bounds read in r_bin_object_set_items
Last modified: 2024-03-07 12:15:24 UTC
radare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bobj.c, causing a crash in r_read_le32 in libr/include/r_endian.h. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-47016
Tracking as affected: - openSUSE:Backports:SLE-15-SP5/radare2 5.8.6 - openSUSE:Factory/radare2 5.8.8 Upstream fix: https://github.com/radareorg/radare2/commit/40c9f50e127be80b9d816bce2ab2ee790831aefd