radare2 5.8.9 has an out-of-bounds read in rbinobjectsetitems in libr/bin/bobj.c, causing a crash in rreadle32 in libr/include/r_endian.h.
{ "vanir_signatures": [ { "deprecated": false, "signature_type": "Function", "source": "https://github.com/radareorg/radare2/commit/40c9f50e127be80b9d816bce2ab2ee790831aefd", "signature_version": "v1", "target": { "file": "libr/bin/p/bin_xnu_kernelcache.c", "function": "r_vector_foreach" }, "digest": { "function_hash": "164460270249102017508017469091217048237", "length": 1236.0 }, "id": "CVE-2023-47016-876b4dfb" }, { "deprecated": false, "signature_type": "Line", "source": "https://github.com/radareorg/radare2/commit/40c9f50e127be80b9d816bce2ab2ee790831aefd", "signature_version": "v1", "target": { "file": "libr/bin/p/bin_xnu_kernelcache.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "21015943817179182943785475345659297815", "198660263838510836744937020636054449556", "257325388403095746107967411419165697968", "83367680598651089277905408982762447568" ] }, "id": "CVE-2023-47016-a35fae3d" } ] }