CVE-2026-5121Disclosure(libarchive / enterprise_linux)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch libarchive enterprise_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • hardened_images
  • libarchive
  • openshift_container_platform

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-30); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
enterprise_linuxhardened_imageslibarchiveopenshift_container_platform

7 versions affected across 4 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Mentions · 2026-04-20: 1Patch / Workaround · 2026-04-20: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-20: 103-3003-3104-20
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-301
Disclosure1
2026-03-311
Disclosure1
2026-04-201
Patch1
Full discourse3 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    CVE‑2026‑5121 – libarchive ISO9660 integer overflow RCE (High): On 32‑bit systems, a crafted ISO9660 image can trigger an integer overflow in zisofs block pointer allocation, leading to a heap buffer overflow and potential arbitrary code execution in anything using libarchive (bsdtar, package managers, file managers). Avoid untrusted ISO images and upgrade libarchive to a patched 3.8.7+ build. https://nvd.nist.gov/vuln/detail/CVE-2026-5121

    Post summary

    The advisory discloses CVE‑2026‑5121 as a 32‑bit integer overflow in libarchive that can lead to RCE, advising users to avoid untrusted ISO images and upgrade to libarchive 3.8.7 or newer.

    1002149
    1.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-5121 - Critical A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a ... https://www.thehackerwire.com/vulnerability/CVE-2026-5121/ https://t.co/1S4rUSVlt7

    Post summary

    A critical integer‑overflow flaw has been disclosed in libarchive’s zisofs block pointer allocation logic on 32‑bit systems, but no proof‑of‑concept, exploit, or patch information is provided.

    0000048
    163 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5121 A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit … https://www.cve.org/CVERecord?id=CVE-2026-5121

    Post summary

    An integer overflow flaw in libarchive’s zisofs block pointer allocation has been disclosed, potentially allowing remote exploitation on 32‑bit systems.

    0000098
    56.8K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Applibarchivelibarchive---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
Appredhathardened_images---
Appredhatopenshift_container_platform4.0--

Explore more