GHSA-2vwv-vqpv-v8vcCriticalCVSS 9.8
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in...
🔗 CVE IDs covered (1)
📋 Description
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
🔗 References (34)
- https://nvd.nist.gov/vuln/detail/CVE-2026-5121
- https://github.com/libarchive/libarchive/pull/2934
- https://access.redhat.com/security/cve/CVE-2026-5121
- https://bugzilla.redhat.com/show_bug.cgi?id=2452945
- https://github.com/advisories/GHSA-2vwv-vqpv-v8vc
- https://access.redhat.com/errata/RHSA-2026:8510
- https://access.redhat.com/errata/RHSA-2026:8517
- https://access.redhat.com/errata/RHSA-2026:8521
- https://access.redhat.com/errata/RHSA-2026:8534
- https://access.redhat.com/errata/RHSA-2026:8867
- https://access.redhat.com/errata/RHSA-2026:8864
- https://access.redhat.com/errata/RHSA-2026:8873
- https://access.redhat.com/errata/RHSA-2026:8908
- https://access.redhat.com/errata/RHSA-2026:8866
- https://access.redhat.com/errata/RHSA-2026:9026
- https://access.redhat.com/errata/RHSA-2026:9592
- https://access.redhat.com/errata/RHSA-2026:9832
- https://access.redhat.com/errata/RHSA-2026:10065
- https://access.redhat.com/errata/RHSA-2026:8944
- https://access.redhat.com/errata/RHSA-2026:11768
- https://access.redhat.com/errata/RHSA-2026:10097
- https://access.redhat.com/errata/RHSA-2026:13812
- https://access.redhat.com/errata/RHSA-2026:14937
- https://access.redhat.com/errata/RHSA-2026:12274
- https://access.redhat.com/errata/RHSA-2026:12071
- https://access.redhat.com/errata/RHSA-2026:16174
- https://access.redhat.com/errata/RHSA-2026:15087
- https://access.redhat.com/errata/RHSA-2026:14773
- https://access.redhat.com/errata/RHSA-2026:16030
- https://access.redhat.com/errata/RHSA-2026:16009
- https://access.redhat.com/errata/RHSA-2026:16008
- https://access.redhat.com/errata/RHSA-2026:17596
- https://access.redhat.com/errata/RHSA-2026:19725
- https://access.redhat.com/errata/RHSA-2026:19724