In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Radare2 | Radare | * | 3.5.1 (including) |
Radare2 | Ubuntu | cosmic | * |
Radare2 | Ubuntu | disco | * |
Radare2 | Ubuntu | eoan | * |
Radare2 | Ubuntu | esm-apps/focal | * |
Radare2 | Ubuntu | focal | * |
Radare2 | Ubuntu | groovy | * |
Radare2 | Ubuntu | lunar | * |
Radare2 | Ubuntu | mantic | * |
Radare2 | Ubuntu | trusty | * |