← Vulnerability feed

Vulnerability record · CVE-2026-4424 · published 19 March 2026

CVE-2026-4424: Libarchive out-of-bounds read vulnerability

Libarchive · Libarchive

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.

7.5 CVSS 3.1 High EPSS 1.1% · top 36.5% CWE-125 · Out-of-bounds read
7.5CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
74References
31 Aug 2026Last modified by NVD

Description

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://access.redhat.com/errata/RHSA-2026:10065 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:10097 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:11768 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:12071
https://access.redhat.com/errata/RHSA-2026:12274
https://access.redhat.com/errata/RHSA-2026:13812
https://access.redhat.com/errata/RHSA-2026:14773
https://access.redhat.com/errata/RHSA-2026:14937
https://access.redhat.com/errata/RHSA-2026:15087
https://access.redhat.com/errata/RHSA-2026:16008
https://access.redhat.com/errata/RHSA-2026:16009
https://access.redhat.com/errata/RHSA-2026:16030
https://access.redhat.com/errata/RHSA-2026:16174
https://access.redhat.com/errata/RHSA-2026:17596
https://access.redhat.com/errata/RHSA-2026:19724
https://access.redhat.com/errata/RHSA-2026:19725
https://access.redhat.com/errata/RHSA-2026:20040
https://access.redhat.com/errata/RHSA-2026:21690
https://access.redhat.com/errata/RHSA-2026:25096
https://access.redhat.com/errata/RHSA-2026:8492 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:8510 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:8517 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:8521 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:8534 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:8864 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:8865 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:8866 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:8867 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:8873 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:8908 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:8944 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:9026 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:9592 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:9832 Third Party Advisory
https://access.redhat.com/security/cve/CVE-2026-4424 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2449006 Issue TrackingThird Party Advisory
https://github.com/libarchive/libarchive/pull/2898 Issue TrackingThird Party Advisory
https://access.redhat.com/errata/RHSA-2026:10065 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:10097 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:11768 Third Party Advisory

Track CVE-2026-4424 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2019-7609Kibana Timelion visualizer code injection enables remote code executionKibana before 5.6.15 and 6.6.1 contains an arbitrary code execution flaw in the Timelion visualizer. An attacker who can reach the Timelion applicati…KEVEPSS 95%analysed9.9CVE-2019-1003029Jenkins Script Security Plugin sandbox bypass allows code executionThe Jenkins Script Security Plugin 1.53 and earlier fails to properly enforce its Groovy sandbox in GroovySandbox.java and SecureGroovyScript.java, l…KEVEPSS 74%analysed9.9CVE-2019-1003030Jenkins Pipeline Groovy Plugin sandbox bypass allows arbitrary code executionThe Jenkins Pipeline: Groovy Plugin (2.63 and earlier) contains a sandbox bypass in CpsGroovyShell.java. Attackers who can control pipeline scripts c…KEVEPSS 97%analysed9.8CVE-2019-5544OpenSLP heap out-of-bounds write in VMware ESXi and Horizon DaaSOpenSLP as shipped in VMware ESXi and Horizon DaaS contains a heap overwrite (out-of-bounds write) flaw. VMware rates it Critical with a maximum CVSS…KEVEPSS 97%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2018-1000861Jenkins Stapler framework URL routing allows remote code executionThe Stapler web framework in Jenkins 2.153 and earlier and LTS 2.138.3 and earlier lets attackers invoke unintended Java methods by requesting crafte…KEVEPSS 98%analysed9.8CVE-2018-14667RichFaces Framework EL injection enables unauthenticated remote code executionRichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language injection through the UserResource resource. A remote, unauthenticated att…KEVEPSS 74%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed

Source: NIST National Vulnerability Database (record CVE-2026-4424), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.