[Git][security-tracker-team/security-tracker][master] Add new radare2 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 23 13:21:25 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b9fb89c9 by Salvatore Bonaccorso at 2026-09-23T14:19:21+02:00
Add new radare2 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1133,23 +1133,54 @@ CVE-2026-81998 (Substance3D - Modeler is affected by an out-of-bounds write vuln
 CVE-2026-81995 (Adobe Experience Manager Forms JEE is affected by an Improper Input Va ...)
 	NOT-FOR-US: Adobe
 CVE-2026-81886 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	TODO: check
+	- radare2 <unfixed>
+	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-3xrx-wh64-8xr8
+	NOTE: https://github.com/radareorg/radare2/issues/26224
+	NOTE: https://github.com/radareorg/radare2/pull/26180
+	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/a7519fdb4da6835c2cecd8fe248e7dd1133cf17a (6.2.0)
 CVE-2026-81885 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	TODO: check
+	- radare2 <unfixed>
+	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-43wr-4j49-rcxj
+	NOTE: https://github.com/radareorg/radare2/issues/26225
+	NOTE: https://github.com/radareorg/radare2/pull/26192
+	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/93d794caa7c2f08413106255d49546e544c1f9f0 (6.2.0)
 CVE-2026-81884 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	TODO: check
+	- radare2 <unfixed>
+	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-c2g2-2mc7-3x5w
+	NOTE: https://github.com/radareorg/radare2/issues/26226
+	NOTE: https://github.com/radareorg/radare2/pull/26193
+	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/a73de09fea7516f65c14917d66113316ec7e7d6e (6.2.0)
 CVE-2026-81883 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	TODO: check
+	- radare2 <unfixed>
+	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-96m5-hvwp-674c
+	NOTE: https://github.com/radareorg/radare2/issues/26228
+	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/26c2eac360033458e9d266e5e30667d1f8d642e3 (6.2.0)
 CVE-2026-81882 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	TODO: check
+	- radare2 <unfixed>
+	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-r5cr-f9p6-5pvj
+	NOTE: https://github.com/radareorg/radare2/issues/26227
+	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/38d82a949626dba3783f40508bb66179e631fa45 (6.2.0)
 CVE-2026-81881 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	TODO: check
+	- radare2 <unfixed>
+	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-q4w7-225g-64j9
+	NOTE: https://github.com/radareorg/radare2/issues/26229
+	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/1da6e782df220edf56138ef5fe4f33745b04db74 (6.2.0)
 CVE-2026-81880 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	TODO: check
+	- radare2 <unfixed>
+	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-fg6f-rj8g-25pq
+	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/87c780e29ee6251cebaab51585d14482cb7740ac (6.2.0)
 CVE-2026-81879 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	TODO: check
+	- radare2 <unfixed>
+	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-jqfq-hvcp-xh4p
+	NOTE: https://github.com/radareorg/radare2/issues/26223
+	NOTE: https://github.com/radareorg/radare2/pull/26178
+	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/9449b07579c19b6b187c1a0918fbec2cef1a036e (6.2.0)
 CVE-2026-81878 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	TODO: check
+	- radare2 <unfixed>
+	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-9phv-v2w8-56j3
+	NOTE: https://github.com/radareorg/radare2/issues/26222
+	NOTE: https://github.com/radareorg/radare2/pull/26177
+	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/6727454b666b28c33837b219a5f91136461357c0 (6.2.0)
 CVE-2026-80156 (Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before fir ...)
 	NOT-FOR-US: Lantronix
 CVE-2026-80155 (Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before fir ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b9fb89c9f735629b1f21b9f2638bbcf78a418f2a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b9fb89c9f735629b1f21b9f2638bbcf78a418f2a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/21577b94/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list