PT-2026-53819 · Unknown · Libarchive

Published

2026-06-30

·

Updated

2026-06-30

·

CVE-2026-14164

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libarchive (affected versions not specified)
Description A double free issue exists in the RAR5 reader of libarchive. When parsing a specially crafted RAR5 archive, the filtered buf pointer may remain stale after being freed during the reinitialization of the unpacking state. If another archive entry is processed, the same memory region may be freed again. This condition can cause applications utilizing the libarchive API to terminate unexpectedly, resulting in a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14164

Affected Products

Libarchive