
CVE‑2026‑5121 – libarchive ISO9660 integer overflow RCE (High): On 32‑bit systems, a crafted ISO9660 image can trigger an integer overflow in zisofs block pointer allocation, leading to a heap buffer overflow and potential arbitrary code execution in anything using libarchive (bsdtar, package managers, file managers). Avoid untrusted ISO images and upgrade libarchive to a patched 3.8.7+ build. https://nvd.nist.gov/vuln/detail/CVE-2026-5121
Post summary
The advisory discloses CVE‑2026‑5121 as a 32‑bit integer overflow in libarchive that can lead to RCE, advising users to avoid untrusted ISO images and upgrade to libarchive 3.8.7 or newer.


