A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libarchive | Sep 1, 2026 | Sep 1, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 19, 2026 | May 24, 2026 |
| Redhat_linux | — | Upgrade libarchive-debugsourceUpgrade libarchive-debuginfoUpgrade bsdunzip-debuginfoUpgrade bsdtar-debuginfoUpgrade bsdtarUpgrade bsdcat-debuginfoUpgrade libarchiveUpgrade bsdcpio-debuginfoUpgrade libarchive-devel | Jul 17, 2026 | May 24, 2026 |
| Rocky_linux | — | Upgrade libarchiveUpgrade libarchive-debuginfoUpgrade bsdtar-debuginfoUpgrade libarchive-debugsourceUpgrade libarchive-develUpgrade bsdtar | Aug 12, 2026 | Aug 11, 2026 |
| Ubuntu | — | Upgrade libarchive-dev (Ubuntu Pro)Upgrade libarchive13t64Upgrade libarchive13 (Ubuntu Pro)Upgrade libarchive-toolsUpgrade libarchive13Upgrade libarchive-tools (Ubuntu Pro)Upgrade libarchive-dev | Jul 22, 2026 | Jul 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub