Debian Package Tracker
Register | Log in
Subscribe

radare2

free and advanced command line hexadecimal editor

Choose email to subscribe with

general
  • source: radare2 (main)
  • version: 6.1.8+ds-1
  • maintainer: Debian Security Tools (DMD)
  • uploaders: Sebastian Reichel [DMD] – Andrej Shadura [DMD] – Alex Myczko [DMD]
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • unstable: 6.1.8+ds-1
versioned links
  • 6.1.8+ds-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libradare2-6.0.0t64
  • libradare2-common
  • libradare2-dev
  • radare2 (1 bugs: 0, 1, 0, 0)
action needed
A new upstream version is available: 6.2.2 high
A new upstream version 6.2.2 is available, you should consider packaging it.
Created: 2026-08-09 Last update: 2026-10-04 06:02
The VCS repository is not up to date, push the missing commits. high
vcswatch reports that the current version of the package is not in its VCS.
Either you need to push your commits and/or your tags, or the information about the package's VCS are out of date. A common cause of the latter issue when using the Git VCS is not specifying the correct branch when the packaging is not in the default one (remote HEAD branch), which is usually "master" but can be modified in salsa.debian.org in the project's general settings with the "Default Branch" field). Alternatively the Vcs-Git field in debian/control can contain a "-b <branch-name>" suffix to indicate what branch is used for the Debian packaging.
Created: 2025-09-24 Last update: 2026-10-01 00:31
9 security issues in sid high

There are 9 open security issues in sid.

9 important issues:
  • CVE-2026-81878: radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal readers accepted a 32-bit string length without rejecting values that overflow the size-plus-one allocation. The vulnerability is triggered by opening or inspecting a crafted .pyc file through r2 or rabin2. A length of 0xffffffff wrapped the allocation to zero before the common byte reader wrote attacker-controlled data and fill bytes beyond the heap allocation. This can cause heap memory corruption and denial of service; arbitrary code execution is possible but has not been demonstrated. This issue is fixed in version 6.2.0.
  • CVE-2026-81879: radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM handling was vulnerable because the ELF parser allocated the program-header array using the resolved PN_XNUM count but several consumers still iterated with the original e_phnum value of 65535. The vulnerability is triggered by processing a crafted ELF file with e_phnum = 0xffff and a much smaller resolved count in shdr[0].sh_info. Consumers iterated beyond the allocated program-header array. This can cause a heap out-of-bounds read and process termination, resulting in denial of service; memory disclosure and code execution have not been demonstrated. This issue is fixed in version 6.2.0.
  • CVE-2026-81880: radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader accepted relocSecCount values that were not bounded by the number of sections or complete relocation records in the input. The vulnerability is triggered by normal binary-format auto-detection of a small crafted Apple PEF file. The loader could perform up to 268,435,456 relocation-section iterations and repeated buffer operations after record offsets passed the end of the file. This can cause denial of service through excessive CPU consumption and prolonged processing. This issue is fixed in version 6.2.0.
  • CVE-2026-81881: radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata section base, making subtraction produce a negative logical index. The vulnerability is triggered by parsing Swift type and class metadata from a crafted Mach-O file. The derived index was used to read four bytes immediately before the allocated field-metadata buffer. This can cause incorrect metadata processing or process termination; no attacker-observable memory disclosure has been demonstrated. This issue is fixed in version 6.2.0.
  • CVE-2026-81882: radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser underallocated an uninitialized UTF-8 destination and did not guarantee NUL termination. The vulnerability is triggered by running the explicit pFB or pFBj commands on untrusted binary property-list data. The json encoder treated the converted data as a nul-terminated c string and could continue reading beyond the allocation. This can cause disclosure of uninitialized or adjacent heap contents in JSON output and possible process termination. This issue is fixed in version 6.2.0.
  • CVE-2026-81883: radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecode function parser was vulnerable because the Lua 5.3 bytecode function parser read fixed function-metadata fields immediately after a function-name string without checking the remaining buffer length. The vulnerability is triggered by opening or inspecting a crafted Lua 5.3 bytecode file whose function-name string ends at the input-buffer boundary. The parser read two integers and three one-byte fields beyond the allocated input buffer. This can cause invalid parser results or process termination; no attacker-observable memory disclosure has been demonstrated. This issue is fixed in version 6.2.0.
  • CVE-2026-81884: radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted dataoff and datasize and allowed a final partial record to be processed. The vulnerability is triggered by opening a crafted Mach-O file while the non-default bin.verbose option is enabled. When datasize was not a multiple of data_in_code_entry, the last iteration read beyond the allocated buffer. This can cause a heap out-of-bounds read and possible process termination; no attacker-observable memory disclosure has been demonstrated. This issue is fixed in version 6.2.0.
  • CVE-2026-81885: radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation fixup-chain parser was vulnerable because the NE relocation parser followed fixup chains without an active iteration limit or cycle detection. The vulnerability is triggered by opening a crafted NE executable whose in-bounds relocation entry points back to itself instead of reaching 0xffff. The parser repeatedly processed the same relocation and allocated another relocation object on each iteration. This can cause denial of service through continuous CPU and memory consumption. This issue is fixed in version 6.2.0.
  • CVE-2026-81886: radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 parser used an input-controlled physical-memory-run PageCount directly as the bound of a per-page allocation loop. The vulnerability is triggered by opening a small crafted full-memory Windows crash dump. The parser repeatedly allocated and appended page descriptors without validating the count against the dump size. This can cause denial of service through excessive memory consumption and processing time. This issue is fixed in version 6.2.0.
Created: 2026-09-23 Last update: 2026-09-24 07:30
lintian reports 193 errors and 290 warnings high
Lintian reports 193 errors and 290 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-06-05 Last update: 2026-07-13 16:46
3 security issues in trixie high

There are 3 open security issues in trixie.

3 important issues:
  • CVE-2025-1378: A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function in the library /libr/main/rasm2.c of the component rasm2. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0.0 is able to address this issue. The patch is identified as c6c772d2eab692ce7ada5a4227afd50c355ad545. It is recommended to upgrade the affected component.
  • CVE-2025-1744: Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffer overflow.This issue affects radare2: before <5.9.9.
  • CVE-2025-1864: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg radare2 allows Overflow Buffers.This issue affects radare2: before <5.9.9.
Created: 2025-02-17 Last update: 2025-03-05 23:32
The package has not entered testing even though the delay is over normal
The package has not entered testing even though the 5-day delay is over. Check why.
Created: 2026-07-18 Last update: 2026-10-03 21:03
debian/patches: 2 patches to forward upstream low

Among the 2 debian patches available in version 6.1.8+ds-1 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2026-06-05 Last update: 2026-07-13 06:02
testing migrations
  • excuses:
    • Migration status for radare2 (- to 6.1.8+ds-1): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ New but not reproduced on amd64 - info: libradare2-6.0.0t64
    • ∙ ∙ New but not reproduced on arm64 - info: libradare2-6.0.0t64
    • ∙ ∙ New but not reproduced on armhf - info: libradare2-6.0.0t64
    • ∙ ∙ New but not reproduced on i386 - info: libradare2-6.0.0t64
    • ∙ ∙ Not touching package due to block request by elbrus (please contact debian-release if update is needed)
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/r/radare2.html
    • ∙ ∙ 83 days old (needed 5 days)
    • Not considered
news
[rss feed]
  • [2026-07-12] Accepted radare2 6.1.8+ds-1 (source) into unstable (Alex Myczko)
  • [2026-06-12] Accepted radare2 6.1.6+ds-3 (source) into unstable (Alex Myczko)
  • [2026-06-04] Accepted radare2 6.1.6+ds-2 (source) into unstable (Alex Myczko)
  • [2026-06-04] Accepted radare2 6.1.6+ds-1 (source) into experimental (Alex Myczko)
  • [2026-05-14] Accepted radare2 6.1.4+ds-1 (source) into experimental (Alex Myczko)
  • [2026-01-02] Accepted radare2 6.0.8+ds-1 (source) into experimental (Alex Myczko)
  • [2025-11-27] Accepted radare2 6.0.7+ds-1 (source) into unstable (Alex Myczko)
  • [2025-09-29] Accepted radare2 6.0.4+dfsg-1 (source) into unstable (Alex Myczko)
  • [2025-09-24] Accepted radare2 6.0.2+dfsg-1 (source amd64 all) into experimental (Debian FTP Masters) (signed by: Alex Myczko)
  • [2025-05-21] radare2 REMOVED from testing (Debian testing watch)
  • [2025-01-19] radare2 5.9.8+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2025-01-13] Accepted radare2 5.9.8+dfsg-2 (source) into unstable (Hilko Bengen)
  • [2024-12-02] Accepted radare2 5.9.8+dfsg-1 (source) into unstable (Alex Myczko) (signed by: Gürkan Myczko)
  • [2024-08-24] Accepted radare2 5.9.4+dfsg-1~bpo12+1 (source amd64 all) into stable-backports (Alex Myczko) (signed by: Gürkan Myczko)
  • [2024-08-16] radare2 5.9.4+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-08-10] Accepted radare2 5.9.4+dfsg-1 (source) into unstable (Alex Myczko) (signed by: Gürkan Myczko)
  • [2024-06-25] Accepted radare2 5.9.2+dfsg-1~bpo12+1 (source amd64 all) into stable-backports (Debian FTP Masters) (signed by: Gürkan Myczko)
  • [2024-05-28] radare2 5.9.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-05-28] radare2 5.9.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-05-23] Accepted radare2 5.9.2+dfsg-1 (source) into unstable (Alex Myczko) (signed by: Gürkan Myczko)
  • [2024-05-08] radare2 5.9.0+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2024-05-02] Accepted radare2 5.9.0+dfsg-2 (source) into unstable (Alex Myczko) (signed by: Gürkan Myczko)
  • [2024-04-25] Accepted radare2 5.9.0+dfsg-1 (source) into unstable (Alex Myczko) (signed by: Gürkan Myczko)
  • [2024-04-15] Accepted radare2 5.8.8+dfsg-1 (source) into experimental (Alex Myczko) (signed by: Gürkan Myczko)
  • [2024-02-29] Accepted radare2 5.5.0+dfsg-1.1 (source) into unstable (Benjamin Drung)
  • [2024-02-03] Accepted radare2 5.5.0+dfsg-1.1~exp1 (source) into experimental (Sergio Durigan Junior)
  • [2021-12-01] Accepted radare2 5.5.0+dfsg-1 (source) into unstable (Andrej Shadura) (signed by: Andrew Shadura)
  • [2021-01-05] Accepted radare2 5.0.0+dfsg-1 (source amd64 all) into unstable, unstable (Debian FTP Masters) (signed by: Sebastian Reichel)
  • [2020-03-27] Accepted radare2 4.3.1+dfsg-1 (source amd64 all) into unstable, unstable (Debian FTP Masters) (signed by: Sebastian Reichel)
  • [2020-02-20] Accepted radare2 4.2.1+dfsg-2 (source) into unstable (Sebastian Reichel)
  • 1
  • 2
bugs [bug history graph]
  • all: 4
  • RC: 0
  • I&N: 2
  • M&W: 1
  • F&P: 1
  • patch: 0
links
  • homepage
  • lintian (193, 290)
  • buildd: logs, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 6.1.8+ds-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing