Vulnerability record · CVE-2024-26256 · published 9 April 2024
CVE-2024-26256: Libarchive heap buffer overflow enables remote code execution
Libarchive · Libarchive
Libarchive contains a heap-based buffer overflow (CWE-122) and out-of-bounds write (CWE-787) that can lead to remote code execution. The flaw is reachable when processing a crafted archive, and it affects libarchive itself plus Fedora and several Windows 11 and Windows Server 2022 releases that bundle it. Because the library is widely embedded, the practical exposure is broad.
Description
Libarchive Remote Code Execution Vulnerability
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with high confidentiality, integrity and availability impact, broad embedded-library exposure, and a very high EPSS score justify high priority despite no KEV listing.
What it is
Libarchive contains a heap-based buffer overflow (CWE-122) and out-of-bounds write (CWE-787) that can lead to remote code execution. The flaw is reachable when processing a crafted archive, and it affects libarchive itself plus Fedora and several Windows 11 and Windows Server 2022 releases that bundle it. Because the library is widely embedded, the practical exposure is broad.
Impact
An attacker who gets a victim to open a malicious archive can corrupt heap memory and potentially execute code in the context of the process using libarchive. That can mean full compromise of confidentiality, integrity and availability for the affected application.
Attack surface
The CVSS vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), so the attacker must deliver a crafted archive that the victim opens with a libarchive-based tool. No authentication is needed, but the victim must take the action of processing the file.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.848 probability, 99.7th percentile), indicating strong predicted exploitation activity. The references include patch commits and release notes, not public exploit code.
What to do
- Update libarchive to version 3.7.4 or later, and apply the corresponding Microsoft, Fedora and Nixpkgs patches.
- Inventory applications and services that embed libarchive and confirm each is rebuilt against the fixed library.
- Restrict processing of untrusted archives to sandboxed or low-privilege processes.
- Warn users not to open archives from untrusted sources until all dependent software is patched.
Detection
- Monitor for crashes or abnormal process terminations in applications that parse archives.
- Hunt for archive files delivered via email or web downloads that are subsequently opened by libarchive-based tools.
- Check endpoint logs for heap corruption indicators or unexpected child processes spawned by archive-handling applications.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-26256 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-26256), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.