CVE-2026-4424Disclosure(libarchive / enterprise_linux)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch libarchive enterprise_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • enterprise_linux_server_aus
  • hardened_images
  • libarchive

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 1 mentions (2026-03-19); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Products
enterprise_linuxenterprise_linux_server_aushardened_imageslibarchiveopenshift_container_platformopenshift_container_platform_for_arm64openshift_container_platform_for_power

10 versions affected across 7 products

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-03-19: 1Mentions · 2026-03-20: 1Mentions · 2026-03-23: 1Mentions · 2026-04-19: 1Mentions · 2026-04-20: 1Patch / Workaround · 2026-04-20: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-23: 1Technical Details · 2026-04-20: 103-1903-2003-2304-1904-20
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-191
Disclosure1
2026-03-201
General1
2026-03-231
Disclosure1
2026-04-191
General1
2026-04-201
Patch1
Full discourse5 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    CVE‑2026‑4424 – libarchive RAR heap out‑of‑bounds read info‑leak (High, CVSS 7.5): Malicious RAR archives abusing LZSS window handling let remote attackers read past heap buffers during decompression, leaking sensitive memory from any app that auto‑processes archives with libarchive. Patch libarchive and treat untrusted RARs as active content, not just “dead” files. https://nvd.nist.gov/vuln/detail/CVE-2026-4424

    Post summary

    The post discloses a heap out‑of‑bounds read info‑leak in libarchive’s RAR handling and recommends applying the patch and treating untrusted RAR files as active content.

    0001032
    1.0K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    General

    libarchive vulnerabilities are like roaches: one shows up (CVE-2026-4424), hundreds more behind it Read now: 👉 https://tinyurl.com/2tvucp9m #Rocky_Linux https://t.co/p9v8JsPDFT

    Post summary

    The tweet briefly mentions a libarchive CVE but provides no substantive technical, exploit, or mitigation details.

    0000057
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4424 A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding win… https://www.cve.org/CVERecord?id=CVE-2026-4424

    Post summary

    The post details a heap OOB read flaw in libarchive’s RAR handling, offering technical specifics but no PoC, exploit, patch, or mention of active exploitation.

    00000117
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-4424 - Red Hat - Red Hat Enterprise Linux 10 - https://www.redpacketsecurity.com/cve-alert-cve-2026-4424-red-hat-red-hat-enterprise-linux-10/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4424 #red-hat #red-hat-enterprise-linux-10

    Post summary

    The tweet merely signals a CVE alert for CVE-2026-4424 on Red Hat Enterprise Linux 10 and links to an external source, providing no detailed technical or exploit information.

    0000075
    3.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4424 Heap Out-of-Bounds Read Vulnerability in Libarchive RAR Archive Processing Logic https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4424

    Post summary

    CVE-2026-4424 is disclosed as a heap out-of-bounds read flaw in Libarchive’s RAR archive handling, with brief technical details but no PoC, exploit, active misuse, or patch information provided.

    0000037
    4.0K followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
Applibarchivelibarchive---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
OSredhatenterprise_linux_server_aus8.2--
OSredhatenterprise_linux_server_aus8.4--
Appredhathardened_images---
Appredhatopenshift_container_platform4.0--
Appredhatopenshift_container_platform4.16--
Appredhatopenshift_container_platform_for_arm644.16--
Appredhatopenshift_container_platform_for_power4.16--

Explore more