
CVE‑2026‑4424 – libarchive RAR heap out‑of‑bounds read info‑leak (High, CVSS 7.5): Malicious RAR archives abusing LZSS window handling let remote attackers read past heap buffers during decompression, leaking sensitive memory from any app that auto‑processes archives with libarchive. Patch libarchive and treat untrusted RARs as active content, not just “dead” files. https://nvd.nist.gov/vuln/detail/CVE-2026-4424
Post summary
The post discloses a heap out‑of‑bounds read info‑leak in libarchive’s RAR handling and recommends applying the patch and treating untrusted RAR files as active content.




