5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Description
A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a segmentation fault and crash the program.
Basic Information
ID
CVE-2025-63744
Source
mitre
Published
Nov 14, 2025 at 00:00
Modified
Nov 14, 2025 at 21:32
Affected Product
Vendor
n/a
Product
n/a
Version
n/a
Affected Versions
n/a n/a n/a
CWE Classification
References
- github.com /marlinkcyber/advisories/blob/main/advisories/radare2-nullptr-deref-bin_dyldcache.md
- github.com /radareorg/radare2/issues/24661
- github.com /radareorg/radare2/commit/e37e15d10fd8a19c3e57b3d7735a2cfe0082ec79
- github.com /marlinkcyber/advisories/blob/main/advisories/MCSAID-2025-002-radare2-nullptr-deref-bin_dyldcache.md