CVE-2017-9949: Radare RADARE2
High severity, CVSS 7.8. EPSS: 1.8% chance of exploitation in the next 30 days.
The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (stack-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a buffer underflow in fs/ext2.c in GNU GRUB 2.02.
Affected products
- Radare RADARE2: version 1.5.0 only
Published 2017-06-26. Last modified 2026-06-17.