CVE-2026-8696Disclosure(radare / radare2)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch radare radare2 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed thread information responses. Attackers can trigger the vulnerability by causing qsThreadInfo to fail after qfThreadInfo successfully allocates RDebugPid structures, resulting in double-free memory corruption when the error path attempts to clean up the list.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • radare2

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-16); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
radare2

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-16: 2Mentions · 2026-06-12: 1Patch / Workaround · 2026-05-16: 1Technical Details · 2026-05-16: 205-1606-12
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-162
Disclosure1Patch1
2026-06-121
General1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-8696 radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of serv… https://www.cve.org/CVERecord?id=CVE-2026-8696

    Post summary

    The text announces CVE-2026-8696, a use‑after‑free bug in radare2’s GDB client core that can lead to remote denial of service. No PoC, exploit, patch, or active exploitation information is provided.

    01020386
    57.8K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 High - Vulnerability in radare2 🚨 CVE-2026-8696 affects radare2 6.1.5 and involves a use-after-free vulnerability in the GDB client core (gdbr_pids_list()). A malicious or malformed GDB server response can trigger memory corruption, potentially leading to: • Denial of Service (DoS) • Arbitrary code execution The issue occurs during thread information parsing and cleanup handling inside the debugger client. 🔧 Recommendation: Avoid connecting to untrusted GDB servers and monitor for updates or patched releases from the radare2 project.

    Post summary

    The post discloses a use‑after‑free flaw in radare2’s GDB client, notes possible DoS and code execution, and urges users to avoid untrusted servers while awaiting vendor updates.

    00011104
    196 followersView on X
  • SAAITAAMAA@saaaadhjj
    General

    A quick read on how Claude code missed finding CVE-2026-8695 & CVE-2026-8696 while a grep() did the work. https://precicom.com/en/techno-blog/grep-your-0days-ai-llms-and-vulnerability-research/

    Post summary

    The brief note references CVE‑2026‑8695 and CVE‑2026‑8696 and notes a grep-based discovery, but provides no further detail on vulnerability specifics, exploitation, or mitigation.

    0010051
    91 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appradareradare2---

Explore more