CVE-2026-40517 - radare2 < 6.1.4 Command Injection via PDB Parser Symbol Names

CVE ID :CVE-2026-40517
Published : April 22, 2026, 10:16 p.m. | 1 hour, 24 minutes ago
Description :radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by crafting a malicious PDB file with newline characters in symbol names. Attackers can inject arbitrary radare2 commands through unsanitized symbol name interpolation in the flag rename command, which are then executed when a user runs the idp command against the malicious PDB file, enabling arbitrary OS command execution through radare2's shell execution operator.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

from Latest Vulnerabilities https://ift.tt/HxVz5kw

Post a Comment

Previous Post Next Post