A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-19 15:16
Updated : 2026-03-20 13:39
NVD link : CVE-2026-4424
Mitre link : CVE-2026-4424
CVE.ORG link : CVE-2026-4424
JSON object : View
Products Affected
No product.
CWE
CWE-125
Out-of-bounds Read
