Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-0518

25
FAUCET Score

CVE-2022-0518 is a heap-based buffer overflow vulnerability affecting radareorg/radare2 prior to version 5.6.2, as well as various Fedora Project distributions of radare2. With a CVSS score of 7.1 (HIGH), this vulnerability can lead to high impact on availability and confidentiality, requiring user interaction and local access for exploitation. Despite its severity, there is currently no evidence of active exploitation, nor are there publicly available exploit modules like Metasploit or Nuclei. Community discussion and media coverage for this CVE are also minimal, indicating low public awareness.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.6.2CPE matchmatch criteria
cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:*
35CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
36CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

6.3MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
3.4
CvssVersion
3.0

Exploit Intelligence

EPSS Score
1.00%
Probability of exploitation in next 30 days
EPSS Percentile
59.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0100 is in the 56th percentile among its peer group of 11,621 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / radareorg/radare2/commit/9650e3c352f675687bf6c6f65ff2c4a3d0e288fa
PatchThird Party Advisory
huntr.dev / bounties/10051adf-7ddc-4042-8fd0-8e9e0c5b1184
ExploitPatchThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/BZTIMAS53YT66FUS4QHQAFRJOBMUFG6D
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/E6YBRQ3UCFWJVSOYIKPVUDASZ544TFND