๐Ÿ” CVE Alert

CVE-2026-45324

LOW 3.3

Rizin: Double free in cmd_search.c

CVSS Score
3.3
EPSS Score
0.0%
EPSS Percentile
0th

Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a double free in librz/core/cmd/cmd_search.c:byte_pattern_search() due wrong pointer ownership declared. This vulnerability is fixed by commit 045fff363b42b8a6dda8ad5229c29ec3267e7dbe.

CWE CWE-415
Vendor rizinorg
Product rizin
Published May 29, 2026
Last Updated May 29, 2026
Stay Ahead of the Next One

Get instant alerts for rizinorg rizin

Be the first to know when new low vulnerabilities affecting rizinorg rizin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L
Attack Vector
Physical
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
Low

Affected Versions

rizinorg / rizin
< 045fff363b42b8a6dda8ad5229c29ec3267e7dbe

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/rizinorg/rizin/security/advisories/GHSA-2377-chx7-xf7c github.com: https://github.com/rizinorg/rizin/commit/045fff363b42b8a6dda8ad5229c29ec3267e7dbe