vulnerability
Red Hat: CVE-2022-26280: CVE-2022-26280 libarchive: an out-of-bounds read via the component zipx_lzma_alone_init (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 6 | (AV:N/AC:M/Au:N/C:P/I:N/A:P) | Mar 28, 2022 | Jul 5, 2022 | Jun 12, 2026 |
Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:P)
Published
Mar 28, 2022
Added
Jul 5, 2022
Modified
Jun 12, 2026
Description
An out-of-bounds read flaw was found in libarchive. This flaw allows an attacker who can supply a specially crafted zip file to libarchive to cause an out-of-bounds read in programs linked with libarchive, using the LZMA zip functionality. The consequences depend on the specific program linked with libarchive. Still, they would most likely result in an application crash or information disclosure that could be used in conjunction with another exploit.
Solutions
redhat-upgrade-bsdcat-debuginforedhat-upgrade-bsdcpio-debuginforedhat-upgrade-bsdtarredhat-upgrade-bsdtar-debuginforedhat-upgrade-libarchiveredhat-upgrade-libarchive-debuginforedhat-upgrade-libarchive-debugsourceredhat-upgrade-libarchive-devel
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.