ZeroHour

CVE-2026-4424

CVSS 3.1
7.5 high
EPSS
1%p67
Published
()
Modified
Description

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.

Vendors
libarchiveredhat
Products
libarchive, hardened images, openshift container platform, openshift container platform for arm64, openshift container platform for power, enterprise linux, enterprise linux server aus
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.