CVE-2026-78322

EUVD-2026-65311
A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a stack buffer overflow and cause file-roller to terminate, resulting in a denial of service. To exploit this flaw, a victim must open or extract the crafted archive using file-roller.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 41.24%
Debian logo
Debian Releases
Debian Product
Codename
file-roller
bookworm
unimportant
forky
44.7-1
fixed
sid
44.7-1
fixed
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
file-roller
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
file-roller
suse enterprise desktop 15 SP7
43.1-150600.3.3.1
fixed
suse enterprise sap 15 SP7
43.1-150600.3.3.1
fixed
suse enterprise server 15 SP4
3.40.0-150400.5.3.1
fixed
suse enterprise server 15 SP7
43.1-150600.3.3.1
fixed
file-roller-lang
suse enterprise desktop 15 SP7
43.1-150600.3.3.1
fixed
suse enterprise sap 15 SP7
43.1-150600.3.3.1
fixed
suse enterprise server 15 SP4
3.40.0-150400.5.3.1
fixed
suse enterprise server 15 SP7
43.1-150600.3.3.1
fixed