HIGH
radare2 < 6.1.4 Command Injection via PDB Parser print_gvars()
Published Apr 15, 2026
8.4
HIGHCVSS 4.0
EPSS 1.70%
Description
radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially crafted section names to inject r2 commands that are executed when the idp command processes the file.
Affected products
-
- Version 0StatusaffectedConstraints<6.1.4
- Version
-
- Version StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-22826 Advisory
- https://github.com/radareorg/radare2/commit/5590c87deeb7eb2a106fd7aab9ca88bfeebb7397 patch
- https://github.com/radareorg/radare2/issues/25752 issue-trackingExploitIssue TrackingThird Party Advisory
- https://github.com/radareorg/radare2/releases/tag/6.1.4 release-notesRelease Notes
- https://www.vulncheck.com/advisories/radare2-command-injection-via-pdb-parser-print-gvars third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-22826 | Advisory | |
| https://github.com/radareorg/radare2/commit/5590c87deeb7eb2a106fd7aab9ca88bfeebb7397 | patch | |
| https://github.com/radareorg/radare2/issues/25752 | issue-trackingExploitIssue TrackingThird Party Advisory | |
| https://github.com/radareorg/radare2/releases/tag/6.1.4 | release-notesRelease Notes | |
| https://www.vulncheck.com/advisories/radare2-command-injection-via-pdb-parser-print-gvars | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 15, 2026
Updated Jul 14, 2026
Reserved Apr 13, 2026
Link CVE-2026-40499
CISA Vulnrichment
Updated Apr 16, 2026
ENISA EUVD
EUVD-2026-22826 Assigner VulnCheck
Published Apr 15, 2026
Updated Jul 14, 2026
Exploited since n/a
Link EUVD-2026-22826