CVE-2026-4424
HIGH EPSS 54.6%
Published Mar 19, 20263mo ago · Modified Jun 17, 20261w ago
7.5 CVSS 3.1
Published Mar 19, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago
Description
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability None
Threat Intelligence
EPSS Exploit Probability
54.6% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-125 Out-of-bounds Read Memory Safety
Affected Products 13
| Vendor | Product | Version | Range |
|---|---|---|---|
| libarchive | libarchive | * | any |
| redhat | hardened_images | * | any |
| redhat | openshift_container_platform | 4.0 | any |
| redhat | openshift_container_platform | 4.16 | any |
| redhat | openshift_container_platform_for_arm64 | 4.16 | any |
| redhat | openshift_container_platform_for_power | 4.16 | any |
| redhat | enterprise_linux | 6.0 | any |
| redhat | enterprise_linux | 7.0 | any |
| redhat | enterprise_linux | 8.0 | any |
| redhat | enterprise_linux | 9.0 | any |
| redhat | enterprise_linux | 10.0 | any |
| redhat | enterprise_linux_server_aus | 8.2 | any |
| redhat | enterprise_linux_server_aus | 8.4 | any |
References 37
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:10065
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:10097
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:11768
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:12071
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:12274
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:13812
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:14773
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:14937
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:15087
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:16008
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:16009
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:16030
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:16174
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:17596
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:19724
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:19725
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:20040
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:21690
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:25096
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:8492
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:8510
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:8517
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:8521
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:8534
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:8864
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:8865
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:8866
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:8867
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:8873
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:8908
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:8944
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:9026
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:9592
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:9832
- access.redhat.com https://access.redhat.com/security/cve/CVE-2026-4424
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2449006
- github.com https://github.com/libarchive/libarchive/pull/2898
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.