5.5
CVSSv3

CVE-2023-30226

Published: 12/07/2023 Updated: 18/07/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An issue exists in function get_gnu_verneed in rizinorg Rizin before 0.5.0 verneed_entry allows malicious users to cause a denial of service via crafted elf file.

Vulnerable Product Search on Vulmon Subscribe to Product

rizin rizin

Github Repositories

rizin denial of service bug

CVE-2023-30226 Rizin is a reverse engineering framework forked from radare2, a flaw was discovered in its ELF parser code that would allow for a crafted file to perform a denial of service This would prevent a user from being able to load the file into rizin but still hold no impact on the execution of the file itself Your average ELF file relies on dynamic linking/loading an