
🚨 HIGH - Double-free in libarchive RAR5 reader via stale filtered_buf pointer (CVE-2026-14164) A double-free vulnerability exists in libarchive’s RAR5 reader component during archive unpacking when handling filtered data buffers. The root cause is a double-free/memory management flaw where the filtered_buf pointer can remain stale after being freed during unpacking state reinitialization. An attacker can exploit this by supplying a specially crafted RAR5 archive that triggers reinitialization and then forces processing of a subsequent entry, causing the same memory to be freed again without needing any special privileges beyond getting the file parsed. Successful exploitation can reliably crash applications and services using the libarchive API (including RH CoreOS tooling paths), resulting in denial of service. 👉 Affected: libarchive (RAR5 reader; versions not specified), rhcos | Upgrade to Vendor patch when available (no fix version provided)
Post summary
CVE-2026-14164 is a high‑severity double‑free bug in libarchive's RAR5 reader that can crash applications when a specially crafted archive is parsed; users should apply the vendor patch as soon as it is released.

