VDB
GHSA-c75f-55f6-f63q
GHSA-c75f-55f6-f63q
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.
Risk Scores
CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Timeline
- Mar 19, 2026 CVE Published
- Apr 10, 2026 Security Advisory
- Apr 17, 2026 Distribution Patch
- Apr 17, 2026 Distribution Patch
- Apr 17, 2026 Distribution Patch
- Apr 17, 2026 Distribution Patch
- Apr 17, 2026 Distribution Patch
- Apr 20, 2026 Distribution Patch
- Apr 21, 2026 Distribution Patch
- Apr 21, 2026 Distribution Patch
- Apr 21, 2026 Distribution Patch
- Apr 21, 2026 Distribution Patch
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-4424 advisory
- https://github.com/libarchive/libarchive/pull/2898 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2449006 url
- https://access.redhat.com/security/cve/CVE-2026-4424 url
- https://access.redhat.com/errata/RHSA-2026:9832 url
- https://access.redhat.com/errata/RHSA-2026:9592 url
- https://access.redhat.com/errata/RHSA-2026:9026 url
- https://access.redhat.com/errata/RHSA-2026:8944 url
- https://access.redhat.com/errata/RHSA-2026:8908 url
- https://access.redhat.com/errata/RHSA-2026:8873 url
- https://access.redhat.com/errata/RHSA-2026:8867 url
- https://access.redhat.com/errata/RHSA-2026:8866 url
- https://access.redhat.com/errata/RHSA-2026:8865 url
- https://access.redhat.com/errata/RHSA-2026:8864 url
- https://access.redhat.com/errata/RHSA-2026:8534 url
- https://access.redhat.com/errata/RHSA-2026:8521 url
- https://access.redhat.com/errata/RHSA-2026:8517 url
- https://access.redhat.com/errata/RHSA-2026:8510 url
- https://access.redhat.com/errata/RHSA-2026:8492 url
- https://access.redhat.com/errata/RHSA-2026:10065 url
…and 9 more