Rapid7

vulnerability

Red Hat: CVE-2022-26280: CVE-2022-26280 libarchive: an out-of-bounds read via the component zipx_lzma_alone_init (Multiple Advisories)

Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:P)
Published
Mar 28, 2022
Added
Jul 5, 2022
Modified
Jun 12, 2026

Description

An out-of-bounds read flaw was found in libarchive. This flaw allows an attacker who can supply a specially crafted zip file to libarchive to cause an out-of-bounds read in programs linked with libarchive, using the LZMA zip functionality. The consequences depend on the specific program linked with libarchive. Still, they would most likely result in an application crash or information disclosure that could be used in conjunction with another exploit.

Solutions

redhat-upgrade-bsdcat-debuginforedhat-upgrade-bsdcpio-debuginforedhat-upgrade-bsdtarredhat-upgrade-bsdtar-debuginforedhat-upgrade-libarchiveredhat-upgrade-libarchive-debuginforedhat-upgrade-libarchive-debugsourceredhat-upgrade-libarchive-devel
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.