CVE Vulnerabilities

CVE-2021-4021

Excessive Iteration

Published: Feb 24, 2022 | Modified: Dec 21, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and DoS.

Weakness

The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.

Affected Software

Name Vendor Start Version End Version
Radare2 Radare * 5.5.0 (including)
Radare2 Ubuntu bionic *
Radare2 Ubuntu lunar *
Radare2 Ubuntu mantic *
Radare2 Ubuntu trusty *
Radare2 Ubuntu xenial *

References