CVE-2026-4424
This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.24% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- libarchive/libarchive · redhat/hardened images · redhat/openshift container platform · redhat/openshift container platform for arm64 · redhat/openshift container platform for power · redhat/enterprise linux · redhat/enterprise linux server aus
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2026:10065Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:10097Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:11768Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:12071
- https://access.redhat.com/errata/RHSA-2026:12274
- https://access.redhat.com/errata/RHSA-2026:13812
- https://access.redhat.com/errata/RHSA-2026:14773
- https://access.redhat.com/errata/RHSA-2026:14937
- https://access.redhat.com/errata/RHSA-2026:15087
- https://access.redhat.com/errata/RHSA-2026:16008
- https://access.redhat.com/errata/RHSA-2026:16009
- https://access.redhat.com/errata/RHSA-2026:16030
- https://access.redhat.com/errata/RHSA-2026:16174
- https://access.redhat.com/errata/RHSA-2026:17596
- https://access.redhat.com/errata/RHSA-2026:19724
- https://access.redhat.com/errata/RHSA-2026:19725
- https://access.redhat.com/errata/RHSA-2026:20040
- https://access.redhat.com/errata/RHSA-2026:21690
- https://access.redhat.com/errata/RHSA-2026:25096
- https://access.redhat.com/errata/RHSA-2026:8492Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:8510Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:8517Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:8521Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:8534Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:8864Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:8865Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:8866Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:8867Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:8873Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:8908Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.