CVE-2025-5645 | Radare2 5.9.9 radiff2 /libr/cons/pal.c r_cons_pal_init -T memory corruption (Issue 24234 / EUVD-2025-16975)
A vulnerability labeled as problematic has been found in Radare2 5.9.9. This affects the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. Such manipulation of the argument -T leads to memory corruption.
This vulnerability is uniquely identified as CVE-2025-5645. Local access is required to approach this attack. Moreover, an exploit is present.
The presence of this vulnerability remains uncertain at this time.
It is advisable to implement a patch to correct this issue.
The documentation explains that the parameter -T is experimental and "crashy". Further analysis has shown "the race is not a real problem unless you use asan". A new warning has been added.