CVE-2026-5121 PUBLISHED CVSS 7.5 HIGH

A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.

EPSS 0.05% · 16.4th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.05%
16.4th percentile

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:3.5.3-7.el9_6.1
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 8.6 Update Services for SAP Solutions0:3.3.3-6.el8_6.1
Red HatRed Hat Enterprise Linux 8.6 Telecommunications Update Service0:3.3.3-6.el8_6.1
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions0:3.3.3-5.el8_8.2
Red HatRed Hat Update Infrastructure 51777454300
Red HatRed Hat Enterprise Linux 9.0 Update Services for SAP Solutions0:3.5.3-2.el9_0.4
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support0:3.3.3-6.el8_6.1
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:3.5.3-5.el9_2.2
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On0:3.3.3-1.el8_4.2
Red HatRed Hat Update Infrastructure 51776868744
Red HatRed Hat Hardened Images3.8.7-1.hum1
Red HatRed Hat Enterprise Linux 9.4 Extended Update Support0:3.5.3-5.el9_4
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support0:3.3.3-1.el8_4.2
redhathardened_images
Red HatRed Hat OpenShift Container Platform 4.16416.94.202604211449-0
redhatenterprise_linux10.0, 6.0, 7.0
Red HatRed Hat Update Infrastructure 51776868842
Red HatRed Hat Enterprise Linux 90:3.5.3-9.el9_7, 0:3.5.3-9.el9_7

…and 13 more

Timeline

References

…and 1 more

Open in Interactive Console →