CVE-2025-5646 is a problematic memory corruption vulnerability in Radare2 versions up to 5.9.9, specifically affecting the r_cons_rainbow_free function within the radiff2 component when manipulating the -T argument. This vulnerability has a CVSS score of 2.5 (LOW), indicating a local attack vector with high attack complexity and a low potential impact of only availability. While a patch (5705d99cc1f23f36f9a84aab26d1724010b97798) is available and the exploit has been publicly disclosed, its real existence is still doubted, and exploitation is considered difficult. There is no evidence of active exploitation, no known Metasploit, Nuclei, or ExploitDB modules, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.9.9CPE matchmatch criteria | cpe:2.3:a:radare:radare2:5.9.9:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.