CVE-2024-26475: Radare RADARE2

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent function.

Affected products

  • Radare RADARE2: from 0.9.7, before 5.8.8 (fixed in 5.8.8)

Published 2024-03-14. Last modified 2026-06-17.