---
title: "CVE-2025-5644\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-5644?format=md
keywords: index, follow
---

# CVE-2025-5644

Publication date 5 June 2025

Last updated 10 July 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**2.5 · Low**

[Score breakdown](https://ubuntu.com/security/CVE-2025-5644?format=md#impact-score)

Toggle side navigation

## Description

A vulnerability, which was classified as problematic, has been found in
Radare2 5.9.9. Affected by this issue is the function r\_cons\_flush in the
library /libr/cons/cons.c of the component radiff2. The manipulation of the
argument -T leads to use after free. Local access is required to approach
this attack. The complexity of an attack is rather high. The exploitation
is known to be difficult. The exploit has been disclosed to the public and
may be used. The real existence of this vulnerability is still doubted at
the moment. The name of the patch is
5705d99cc1f23f36f9a84aab26d1724010b97798. It is recommended to apply a
patch to fix this issue. The documentation explains that the parameter -T
is experimental and "crashy". Further analysis has shown "the race is not a
real problem unless you use asan". A new warning has been added.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2025-5644?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| radare2 | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 25.04 plucky | Ignored end of life, was needs-triage |
| 24.10 oracular | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [rodrigo-zaiden](https://launchpad.net/~rodrigo-zaiden)

there is no real fix for this. commit 5705d99cc1f23f36f9a84aab26d1724010b97798
is adding a warning log about the risk of using '-T'

## Severity score breakdown

CVSS version:

CVSS v4.0

[CVSS v4.0](https://ubuntu.com/security/CVE-2025-5644?format=md)
[CVSS v3.0](https://ubuntu.com/security/CVE-2025-5644?format=md)

**Base score**

2.0 · Low

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | High |
  | Attack requirements | None |
  | Privileges required | Low |
  | User interaction | None |
  | Vulnerable system - Confidentiality impact | None |
  | Vulnerable system - Integrity impact | None |
  | Vulnerable system - Availability impact | Low |
  | Subsequent system - Confidentiality impact | None |
  | Subsequent system - Integrity impact | None |
  | Subsequent system - Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 2.0 · Low |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5644)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-5644)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-5644)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-5644)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-5644>
* <https://github.com/radareorg/radare2/issues/24233>
* <https://github.com/radareorg/radare2/commit/5705d99cc1f23f36f9a84aab26d1724010b97798>
* <https://drive.google.com/file/d/1VtiMMp7ECun3sq3AwlqQrU9xEPA45eOz/view?usp=sharing>
* <https://github.com/radareorg/radare2/issues/24233#issuecomment-2918847833>
* <https://vuldb.com/?ctiid.311132>
* <https://vuldb.com/?id.311132>
* <https://vuldb.com/?submit.586921>
