Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4426

Опубликовано: 19 мар. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (pz_log2_bs) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.

Отчет

This MODERATE impact vulnerability in libarchive's zisofs decompression logic can lead to a denial of service. The flaw is triggered when processing a specially crafted ISO9660 image containing an invalid shift exponent. Red Hat products that process untrusted ISO files using libarchive are susceptible to crashes.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted ISO9660 images with libarchive. Restricting the sources of ISO files and ensuring they originate from trusted entities can prevent exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libarchiveFix deferred
Red Hat Enterprise Linux 6libarchiveOut of support scope
Red Hat Enterprise Linux 7libarchiveFix deferred
Red Hat Enterprise Linux 8libarchiveFix deferred
Red Hat Enterprise Linux 9libarchiveFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1335
https://bugzilla.redhat.com/show_bug.cgi?id=2449010libarchive: libarchive: Denial of Service via malformed ISO file processing

EPSS

Процентиль: 31%
0.00122
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
21 день назад

A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.

CVSS3: 6.5
nvd
21 день назад

A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.

msrc
9 дней назад

Libarchive: libarchive: denial of service via malformed iso file processing

CVSS3: 6.5
debian
21 день назад

A flaw was found in libarchive. An Undefined Behavior vulnerability ex ...

CVSS3: 6.5
github
21 день назад

A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.

EPSS

Процентиль: 31%
0.00122
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2026-4426