CVE-2026-4424 Details
Description
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.
A heap out-of-bounds read vulnerability has been identified in the libarchive library, specifically within the RAR archive processing logic. This vulnerability arises from inadequate validation of the LZSS sliding window size following transitions between compression methods, particularly PPMd and LZSS. As a result, the copy_from_lzss_window() function can perform out-of-bounds memory reads, leading to the unintentional disclosure of sensitive heap memory information. This vulnerability can be exploited remotely, without authentication or user interaction, on systems that automatically process untrusted RAR archives.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | redhat-SADP |
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| libarchive libarchive | All versions |
CPE
Remediation
| |
| redhat hardened images | All versions |
CPE
Remediation
| |
| redhat openshift container platform | 4.0 4.16 |
CPE
Remediation
| |
| redhat openshift container platform for arm64 | 4.16 |
CPE
Remediation
| |
| redhat openshift container platform for power | 4.16 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
| redhat enterprise linux server aus | 8.2 8.4 |
CPE
Remediation
| |
Change History
37 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 31, 2026 | CVE Modified | redhat-SADP |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 10, 2026 | CVE Modified | [email protected] |
| Jun 4, 2026 | CVE Modified | [email protected] |
| May 28, 2026 | CVE Modified | [email protected] |
| May 21, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 14, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Modified | [email protected] |
| May 12, 2026 | CVE Modified | [email protected] |
| May 11, 2026 | CVE Modified | [email protected] |
| May 9, 2026 | CVE Modified | [email protected] |
| May 7, 2026 | CVE Modified | [email protected] |
| May 5, 2026 | CVE Modified | [email protected] |
| Apr 30, 2026 | Initial Analysis | [email protected] |
| Apr 30, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | CVE Modified | [email protected] |
| Apr 23, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | CVE Modified | [email protected] |
| Apr 20, 2026 | CVE Modified | [email protected] |
| Apr 20, 2026 | CVE Modified | [email protected] |
| Apr 20, 2026 | CVE Modified | [email protected] |
| Apr 20, 2026 | CVE Modified | [email protected] |
| Apr 20, 2026 | CVE Modified | [email protected] |
| Apr 20, 2026 | CVE Modified | [email protected] |
| Apr 16, 2026 | CVE Modified | [email protected] |
| Apr 16, 2026 | CVE Modified | [email protected] |
| Apr 16, 2026 | CVE Modified | [email protected] |
| Apr 16, 2026 | CVE Modified | [email protected] |
| Mar 19, 2026 | New CVE Received | [email protected] |