CVE-2021-3674

HIGH

Rizin < 0.2.1 - Memory Corruption

Title source: rule
STIX 2.1

Description

A flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the headers. Crafted values in the headers can cause out of bounds reads, which can lead to memory corruption and possibly code execution through the binary object's callback function.

References (2)

Core 2
Core References
Exploit, Patch, Vendor Advisory
https://github.com/rizinorg/rizin/pull/1313

Scores

CVSS v3 7.8
EPSS 0.0018
EPSS Percentile 38.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-125
Status published
Products (1)
rizin/rizin < 0.2.1
Published Mar 24, 2023
Tracked Since Feb 18, 2026