CVE-2025-5641 describes a memory corruption vulnerability in Radare2 version 5.9.9, specifically within the r_cons_is_breaked function in the radiff2 component, triggered by manipulating the -T argument. This vulnerability has a low severity CVSS score of 2.5, indicating a local attack vector with high attack complexity and a low impact on availability. While public exploit disclosure exists, its real existence is doubted, and there is no evidence of active exploitation, exploit code in common frameworks, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.9.9CPE matchmatch criteria | cpe:2.3:a:radare:radare2:5.9.9:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.