CVE-2026-4424
EUVD-2026-1309719.03.2026, 15:16
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libarchive | libarchive | - |
| redhat | hardened_images | - |
| redhat | openshift_container_platform | 4.0 |
| redhat | openshift_container_platform | 4.16 |
| redhat | openshift_container_platform_for_arm64 | 4.16 |
| redhat | openshift_container_platform_for_power | 4.16 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
| redhat | enterprise_linux_server_aus | 8.2 |
| redhat | enterprise_linux_server_aus | 8.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| bsdtar |
| ||||||||||||||||||
| libarchive |
| ||||||||||||||||||
| libarchive-devel |
|
Common Weakness Enumeration
Vulnerability Media Exposure
References