CVE-2025-5646 | Radare2 5.9.9 radiff2 /libr/cons/pal.c r_cons_rainbow_free -T memory corruption (Issue 24235 / EUVD-2025-16974)
A vulnerability marked as problematic has been reported in Radare2 5.9.9. This impacts the function r_cons_rainbow_free in the library /libr/cons/pal.c of the component radiff2. Performing manipulation of the argument -T results in memory corruption.
This vulnerability was named CVE-2025-5646. The attack needs to be approached locally. In addition, an exploit is available.
There are still doubts about whether this vulnerability truly exists.
Applying a patch is the recommended action to fix this issue.
The documentation explains that the parameter -T is experimental and "crashy". Further analysis has shown "the race is not a real problem unless you use asan". A new warning has been added.