CVE-2025-5647 | Radare2 5.9.9 radiff2 /libr/cons/cons.c r_cons_context_break_pop -T memory corruption (Issue 24237 / EUVD-2025-16978)
A vulnerability described as problematic has been identified in Radare2 5.9.9. Affected is the function r_cons_context_break_pop in the library /libr/cons/cons.c of the component radiff2. Executing manipulation of the argument -T can lead to memory corruption.
The identification of this vulnerability is CVE-2025-5647. The attack can only be executed locally. Furthermore, there is an exploit available.
There is ongoing doubt regarding the real existence of this vulnerability.
It is best practice to apply a patch to resolve this issue.
The documentation explains that the parameter -T is experimental and "crashy". Further analysis has shown "the race is not a real problem unless you use asan". A new warning has been added.