CVE-2026-24857Disclosure(simsong / bulk_extractor)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch simsong bulk_extractor systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

`bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar code has a heap‑buffer‑overflow in the RAR PPM LZ decoding path. A crafted RAR inside a disk image causes an out‑of‑bounds write in `Unpack::CopyString`, leading to a crash under ASAN (and likely a crash or memory corruption in production builds). There's potential for using this for RCE. As of time of publication, no known patches are available.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bulk_extractor

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-01-28); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
bulk_extractor

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-01-28: 2Mentions · 2026-08-02: 1Mentions · 2026-08-18: 1Patch / Workaround · 2026-08-02: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-01-28: 201-2808-0208-18
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-282
Disclosure2
2026-08-021
Patch1
2026-08-181
Patch1
Full discourse4 posts
  • Simson Garfinkel@xchatty
    Patch

    I am looking for help to test bulk_extractor release 2.2.0. The new release closes over 83 open issues and resolves CVE-2026-24857. Most of the work was done by AI with my guidance. The progress has been phenomenal. #DFIR Here's what's been fixed: https://github.com/simsong/bulk_extractor/milestone/6?closed=1

    Post summary

    Bulk_extractor 2.2.0 has been released to patch CVE-2026-24857, with no mention of exploits or active attacks.

    34052627
    2.2K followersView on X
  • Simson Garfinkel@xchatty
    Patch

    bulk_extractor 2.2.0 is out: a security and reliability release fixing CVE-2026-24857, with a standalone 64-bit Windows build, Windows raw-device input, runtime scanner plug-ins, improved Wi-Fi PCAP handling, and more. https://github.com/simsong/bulk_extractor/releases/tag/v2.2.0 #DFIR #DigitalForensics

    Post summary

    Bulk_extractor 2.2.0 released, providing a patch for CVE-2026-24857 along with several new features.

    15061362
    2.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24857 Heap Buffer Overflow in Bulk Extractor RAR Decoding Mechanism Before 1.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24857

    Post summary

    This notice announces a new heap buffer overflow vulnerability (CVE-2026-24857) affecting Bulk Extractor's RAR decoding component before version 1.4. No exploit or mitigation details are provided.

    0000053
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24857 `bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar code has a heap‑buffer‑overflow in the RAR PPM L… https://www.cve.org/CVERecord?id=CVE-2026-24857

    Post summary

    A heap‑buffer‑overflow vulnerability was identified in bulk_extractor’s embedded unrar code, beginning with version 1.4.

    00000282
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsimsongbulk_extractor---

Explore more