CVE-2026-5121 Details
Description
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
An integer overflow vulnerability has been identified in libarchive, specifically in the zisofs block pointer allocation logic on 32-bit systems. This flaw can be exploited by remote attackers who provide specially crafted ISO9660 images, leading to a heap buffer overflow. Such an overflow could potentially allow arbitrary code execution on the affected system.
To mitigate this vulnerability, avoid processing untrusted ISO9660 images with applications that use libarchive. Only extract or read content from ISO images obtained from trusted sources.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | CISA-ADP |
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| libarchive libarchive | All versions |
CPE
Remediation
| |
| redhat hardened images | All versions |
CPE
Remediation
| |
| redhat openshift container platform | 4.0 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
38 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | CVE Modified | siemens-SADP |
| Sep 1, 2026 | CVE Modified | [email protected] |
| Jul 14, 2026 | CVE Modified | siemens-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 10, 2026 | CVE Modified | [email protected] |
| Jun 4, 2026 | CVE Modified | [email protected] |
| May 28, 2026 | CVE Modified | [email protected] |
| May 21, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 14, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Modified | [email protected] |
| May 12, 2026 | CVE Modified | [email protected] |
| May 11, 2026 | CVE Modified | [email protected] |
| May 9, 2026 | CVE Modified | [email protected] |
| May 7, 2026 | CVE Modified | [email protected] |
| May 5, 2026 | CVE Modified | [email protected] |
| Apr 30, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | CVE Modified | [email protected] |
| Apr 23, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | CVE Modified | [email protected] |
| Apr 20, 2026 | CVE Modified | [email protected] |
| Apr 20, 2026 | CVE Modified | [email protected] |
| Apr 20, 2026 | CVE Modified | [email protected] |
| Apr 20, 2026 | CVE Modified | [email protected] |
| Apr 20, 2026 | CVE Modified | [email protected] |
| Apr 20, 2026 | CVE Modified | [email protected] |
| Apr 16, 2026 | CVE Modified | [email protected] |
| Apr 16, 2026 | CVE Modified | [email protected] |
| Apr 16, 2026 | CVE Modified | [email protected] |
| Apr 14, 2026 | CVE Modified | [email protected] |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Apr 14, 2026 | CVE Modified | [email protected] |
| Mar 31, 2026 | CVE Modified | CISA-ADP |
| Mar 30, 2026 | New CVE Received | [email protected] |