Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78322

Опубликовано: 24 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a stack buffer overflow and cause file-roller to terminate, resulting in a denial of service. To exploit this flaw, a victim must open or extract the crafted archive using file-roller.

Отчет

This flaw in file-roller can lead to a denial of service when processing specially crafted 7z or RAR archives. The vulnerability, a stack buffer overflow, occurs when file paths from archive entries exceed fixed-size buffers during progress line parsing, causing the application to terminate. Exploitation requires user interaction and is difficult for arbitrary code execution on hardened Red Hat systems.

Меры по смягчению последствий

Avoid opening or extracting untrusted 7z or RAR archives with file-roller until an updated package is installed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6file-rollerFix deferred
Red Hat Enterprise Linux 7file-rollerFix deferred
Red Hat Enterprise Linux 8file-rollerFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2521767file-roller: file-roller: stack buffer overflow in parse_progress_line for 7z and RAR handlers

EPSS

Процентиль: 21%
0.00282
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
23 дня назад

A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a stack buffer overflow and cause file-roller to terminate, resulting in a denial of service. To exploit this flaw, a victim must open or extract the crafted archive using file-roller.

CVSS3: 6.5
nvd
23 дня назад

A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a stack buffer overflow and cause file-roller to terminate, resulting in a denial of service. To exploit this flaw, a victim must open or extract the crafted archive using file-roller.

CVSS3: 6.5
debian
23 дня назад

A flaw was found in file-roller. When opening or extracting a maliciou ...

suse-cvrf
21 день назад

Security update for file-roller

CVSS3: 6.5
github
23 дня назад

A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a stack buffer overflow and cause file-roller to terminate, resulting in a denial of service. To exploit this flaw, a victim must open or extract the crafted archive using file-roller.

EPSS

Процентиль: 21%
0.00282
Низкий

6.5 Medium

CVSS3