CVE-2026-40499
EUVD-2026-2282615.04.2026, 04:17
radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially crafted section names to inject r2 commands that are executed when the idp command processes the file.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| radare | radare2 | 𝑥 ≤ 6.1.4 |
𝑥
= Vulnerable software versions