A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-03-19 15:16
Updated : 2026-08-31 17:17
NVD link : CVE-2026-4424
Mitre link : CVE-2026-4424
CVE.ORG link : CVE-2026-4424
JSON object : View
Products Affected
redhat
- openshift_container_platform_for_arm64
- enterprise_linux
- enterprise_linux_server_aus
- openshift_container_platform
- hardened_images
- openshift_container_platform_for_power
libarchive
- libarchive
CWE
CWE-125
Out-of-bounds Read
