Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 15 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Double Free in Rizin LE Loader Causing Denial of Service |
Tue, 14 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:rizin:rizin:0.8.1:*:*:*:*:*:*:* |
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Double Free in Rizin LE Loader Causing Denial of Service |
Tue, 07 Apr 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Heap Double‑Free in Rizin LE Binary Loader Leading to Denial of Service | |
| Weaknesses | CWE-416 |
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Heap Double‑Free in Rizin LE Binary Loader Leading to Denial of Service | |
| First Time appeared |
Rizin
Rizin rizin |
|
| Weaknesses | CWE-415 CWE-416 |
|
| Vendors & Products |
Rizin
Rizin rizin |
|
| Metrics |
cvssV3_1
|
Mon, 06 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A double free vulnerability exists in librz/bin/format/le/le.c in the function le_load_fixup_record(). When processing malformed or circular LE fixup chains, relocation entries may be freed multiple times during error handling. A specially crafted LE binary can trigger heap corruption and cause the application to crash, resulting in a denial-of-service condition. An attacker with a crafted binary could cause a denial of service when the tool is integrated on a service pipeline. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-06T19:42:43.611Z
Reserved: 2026-03-09T00:00:00.000Z
Link: CVE-2026-31053
Updated: 2026-04-06T19:42:15.663Z
Status : Analyzed
Published: 2026-04-06T15:17:07.953
Modified: 2026-04-14T19:12:31.837
Link: CVE-2026-31053
No data.
OpenCVE Enrichment
Updated: 2026-04-15T16:30:09Z