A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libarchiveUpgrade libarchive-develUpgrade bsdtar | Apr 20, 2026 | Apr 16, 2026 |
| Apple Osx Libarchive | — | Upgrade macOS to the latest version | Sep 10, 2026 | Jul 27, 2026 |
| Debian | — | Upgrade libarchive | May 6, 2026 | May 6, 2026 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Jun 2, 2026 |
| Oracle_linux | — | Upgrade libarchive-develUpgrade bsdtarUpgrade libarchive | Apr 22, 2026 | Mar 19, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Mar 19, 2026 |
| Redhat_linux | — | Upgrade bsdcat-debuginfoUpgrade bsdcpio-debuginfoUpgrade libarchive-debuginfoUpgrade bsdunzip-debuginfoUpgrade libarchiveUpgrade bsdcpioUpgrade libarchive-develUpgrade bsdtar-debuginfoUpgrade libarchive-debugsourceNo solution existsUpgrade bsdtar | Apr 17, 2026 | Mar 19, 2026 |
| Rocky_linux | — | Upgrade libarchiveUpgrade bsdtarUpgrade libarchive-develUpgrade libarchive-debugsourceUpgrade libarchive-debuginfoUpgrade bsdtar-debuginfo | Apr 20, 2026 | Apr 18, 2026 |
| Suse | — | Upgrade libarchive13Upgrade libarchive-develUpgrade bsdtar | Jun 1, 2026 | Apr 18, 2026 |
| Ubuntu | — | Upgrade bsdcpio (Ubuntu Pro)Upgrade libarchive13 (Ubuntu Pro)Upgrade libarchive13t64Upgrade libarchive13Upgrade bsdtar (Ubuntu Pro)Upgrade libarchive-toolsUpgrade libarchive-dev (Ubuntu Pro)Upgrade libarchive-devUpgrade libarchive-tools (Ubuntu Pro) | May 25, 2026 | May 21, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Mar 19, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub