PT-2026-28808 · Unknown+4 · Libarchive+4

Carnil

·

Publicado

2026-01-01

·

Atualizado

2026-05-28

·

CVE-2026-5121

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libarchive (affected versions not specified)
Description An integer overflow exists in the zisofs block pointer allocation logic on 32-bit systems. A remote attacker can exploit this by providing a specially crafted ISO9660 image, potentially leading to a heap buffer overflow and arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2026:8510
ALSA-2026:8534
BDU:2026-07332
CVE-2026-5121
ECHO-FE78-E324-D857
OESA-2026-1940
OESA-2026-1941
OESA-2026-1942
OESA-2026-1943
OESA-2026-1944
OESA-2026-1945
RHSA-2026:8510
RHSA-2026:8517
RHSA-2026:8521
RHSA-2026:8534
RHSA-2026:8864
RHSA-2026:8866
RHSA-2026:8867
RHSA-2026:8873
RHSA-2026:8908
RHSA-2026:8944
RHSA-2026:9026
RHSA-2026:9592
USN-8292-1

Produtos afetados

Linuxmint
Red Os
Rocky Linux
Ubuntu
Libarchive