CVE-2025-5648 describes a memory corruption vulnerability in Radare2 version 5.9.9, specifically within the r_cons_pal_init function in the radiff2 component, triggered by manipulating the -T argument. This vulnerability has a low CVSS score of 2.5, indicating local access and high attack complexity, with a limited impact on availability. While a patch exists and the exploit has been publicly disclosed, its real existence is currently doubted, and there is no evidence of active exploitation or readily available exploit intelligence. Community discussion and media coverage are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.9.9CPE matchmatch criteria | cpe:2.3:a:radare:radare2:5.9.9:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.