---
title: "CVE-2025-5643\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-5643?format=md
keywords: index, follow
---

# CVE-2025-5643

Publication date 5 June 2025

Last updated 10 July 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**2.5 · Low**

[Score breakdown](https://ubuntu.com/security/CVE-2025-5643?format=md#impact-score)

Toggle side navigation

## Description

A vulnerability classified as problematic was found in Radare2 5.9.9.
Affected by this vulnerability is the function cons\_stack\_load in the
library /libr/cons/cons.c of the component radiff2. The manipulation of the
argument -T leads to memory corruption. An attack has to be approached
locally. The complexity of an attack is rather high. The exploitation
appears to be difficult. The exploit has been disclosed to the public and
may be used. The real existence of this vulnerability is still doubted at
the moment. The patch is named 5705d99cc1f23f36f9a84aab26d1724010b97798. It
is recommended to apply a patch to fix this issue. The documentation
explains that the parameter -T is experimental and "crashy". Further
analysis has shown "the race is not a real problem unless you use asan". A
new warning has been added.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2025-5643?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| radare2 | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 25.04 plucky | Ignored end of life, was needs-triage |
| 24.10 oracular | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [rodrigo-zaiden](https://launchpad.net/~rodrigo-zaiden)

there is no real fix for this. commit 5705d99cc1f23f36f9a84aab26d1724010b97798
is adding a warning log about the risk of using '-T'

## Severity score breakdown

CVSS version:

CVSS v4.0

[CVSS v4.0](https://ubuntu.com/security/CVE-2025-5643?format=md)
[CVSS v3.0](https://ubuntu.com/security/CVE-2025-5643?format=md)

**Base score**

2.0 · Low

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | High |
  | Attack requirements | None |
  | Privileges required | Low |
  | User interaction | None |
  | Vulnerable system - Confidentiality impact | None |
  | Vulnerable system - Integrity impact | None |
  | Vulnerable system - Availability impact | Low |
  | Subsequent system - Confidentiality impact | None |
  | Subsequent system - Integrity impact | None |
  | Subsequent system - Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 2.0 · Low |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5643)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-5643)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-5643)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-5643)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-5643>
* <https://github.com/radareorg/radare2/issues/24232>
* <https://github.com/radareorg/radare2/commit/5705d99cc1f23f36f9a84aab26d1724010b97798>
* <https://drive.google.com/file/d/1XsoyD7lMC-9a9Cxhld8sdEE-0PF3lxvB/view?usp=sharing>
* <https://github.com/radareorg/radare2/issues/24232#issuecomment-2918841776>
* <https://vuldb.com/?ctiid.311131>
* <https://vuldb.com/?id.311131>
* <https://vuldb.com/?submit.586912>
