PT-2026-53819 · Unknown · Libarchive
Published
2026-06-30
·
Updated
2026-06-30
·
CVE-2026-14164
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libarchive (affected versions not specified)
Description
A double free issue exists in the RAR5 reader of libarchive. When parsing a specially crafted RAR5 archive, the
filtered buf pointer may remain stale after being freed during the reinitialization of the unpacking state. If another archive entry is processed, the same memory region may be freed again. This condition can cause applications utilizing the libarchive API to terminate unexpectedly, resulting in a denial of service.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libarchive