|
3 | 3 | "enisaUuid": "e56690d0-bd77-3749-b1dc-cfa65800ac55", |
4 | 4 | "description": "A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.", |
5 | 5 | "datePublished": "Mar 19, 2026, 1:50:27 PM", |
6 | | - "dateUpdated": "Apr 30, 2026, 12:47:07 PM", |
| 6 | + "dateUpdated": "May 9, 2026, 12:08:34 AM", |
7 | 7 | "baseScore": 7.5, |
8 | 8 | "baseScoreVersion": "3.1", |
9 | 9 | "baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", |
10 | | - "references": "https://access.redhat.com/errata/RHSA-2026:10065\nhttps://access.redhat.com/errata/RHSA-2026:10097\nhttps://access.redhat.com/errata/RHSA-2026:11768\nhttps://access.redhat.com/errata/RHSA-2026:8492\nhttps://access.redhat.com/errata/RHSA-2026:8510\nhttps://access.redhat.com/errata/RHSA-2026:8517\nhttps://access.redhat.com/errata/RHSA-2026:8521\nhttps://access.redhat.com/errata/RHSA-2026:8534\nhttps://access.redhat.com/errata/RHSA-2026:8864\nhttps://access.redhat.com/errata/RHSA-2026:8865\nhttps://access.redhat.com/errata/RHSA-2026:8866\nhttps://access.redhat.com/errata/RHSA-2026:8867\nhttps://access.redhat.com/errata/RHSA-2026:8873\nhttps://access.redhat.com/errata/RHSA-2026:8908\nhttps://access.redhat.com/errata/RHSA-2026:8944\nhttps://access.redhat.com/errata/RHSA-2026:9026\nhttps://access.redhat.com/errata/RHSA-2026:9592\nhttps://access.redhat.com/errata/RHSA-2026:9832\nhttps://access.redhat.com/security/cve/CVE-2026-4424\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2449006\nhttps://github.com/libarchive/libarchive/pull/2898\n", |
| 10 | + "references": "https://access.redhat.com/errata/RHSA-2026:10065\nhttps://access.redhat.com/errata/RHSA-2026:10097\nhttps://access.redhat.com/errata/RHSA-2026:11768\nhttps://access.redhat.com/errata/RHSA-2026:12274\nhttps://access.redhat.com/errata/RHSA-2026:13812\nhttps://access.redhat.com/errata/RHSA-2026:14937\nhttps://access.redhat.com/errata/RHSA-2026:8492\nhttps://access.redhat.com/errata/RHSA-2026:8510\nhttps://access.redhat.com/errata/RHSA-2026:8517\nhttps://access.redhat.com/errata/RHSA-2026:8521\nhttps://access.redhat.com/errata/RHSA-2026:8534\nhttps://access.redhat.com/errata/RHSA-2026:8864\nhttps://access.redhat.com/errata/RHSA-2026:8865\nhttps://access.redhat.com/errata/RHSA-2026:8866\nhttps://access.redhat.com/errata/RHSA-2026:8867\nhttps://access.redhat.com/errata/RHSA-2026:8873\nhttps://access.redhat.com/errata/RHSA-2026:8908\nhttps://access.redhat.com/errata/RHSA-2026:8944\nhttps://access.redhat.com/errata/RHSA-2026:9026\nhttps://access.redhat.com/errata/RHSA-2026:9592\nhttps://access.redhat.com/errata/RHSA-2026:9832\nhttps://access.redhat.com/security/cve/CVE-2026-4424\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2449006\nhttps://github.com/libarchive/libarchive/pull/2898\n", |
11 | 11 | "aliases": "CVE-2026-4424\n", |
12 | 12 | "assigner": "redhat", |
13 | | - "epss": 0.3, |
| 13 | + "epss": 0.36, |
14 | 14 | "enisaIdProduct": [ |
15 | 15 | { |
16 | 16 | "id": "05626d50-27c6-3681-96e1-5ea1ea171357", |
|
54 | 54 | }, |
55 | 55 | "product_version": "patch: 0:3.3.3-6.el8_6.1" |
56 | 56 | }, |
| 57 | + { |
| 58 | + "id": "24a88f97-354e-36f3-9b42-41df316be4aa", |
| 59 | + "product": { |
| 60 | + "name": "RHEL-8 based Middleware Containers" |
| 61 | + }, |
| 62 | + "product_version": "patch: 7.13.5-3.1777325680" |
| 63 | + }, |
57 | 64 | { |
58 | 65 | "id": "2d6aa4b8-b701-3247-9a7d-29979268e057", |
59 | 66 | "product": { |
60 | 67 | "name": "Red Hat Update Infrastructure 5" |
61 | 68 | }, |
62 | 69 | "product_version": "patch: 1776868774" |
63 | 70 | }, |
| 71 | + { |
| 72 | + "id": "2f9ce043-df34-3ae8-8c6e-b217e3cfd13d", |
| 73 | + "product": { |
| 74 | + "name": "RHEL-8 based Middleware Containers" |
| 75 | + }, |
| 76 | + "product_version": "patch: 7.13.5-4.1777325708" |
| 77 | + }, |
64 | 78 | { |
65 | 79 | "id": "2fd13481-e2cb-3256-ae54-6493d8d0b55c", |
66 | 80 | "product": { |
|
75 | 89 | }, |
76 | 90 | "product_version": "patch: 3.8.7-1.hum1" |
77 | 91 | }, |
| 92 | + { |
| 93 | + "id": "3e5a3c34-7cf5-3afa-a73d-1f76ab3980ea", |
| 94 | + "product": { |
| 95 | + "name": "RHEL-8 based Middleware Containers" |
| 96 | + }, |
| 97 | + "product_version": "patch: 7.13.5-4.1777325710" |
| 98 | + }, |
78 | 99 | { |
79 | 100 | "id": "4d115ff4-89e1-3aa0-adc5-f0aa11f6467e", |
80 | 101 | "product": { |
|
96 | 117 | }, |
97 | 118 | "product_version": "patch: 0:3.1.2-14.el7_9.2" |
98 | 119 | }, |
| 120 | + { |
| 121 | + "id": "59072756-0d7a-3043-95bd-e0e1d8934f2b", |
| 122 | + "product": { |
| 123 | + "name": "Red Hat Discovery 2" |
| 124 | + }, |
| 125 | + "product_version": "patch: 1778101579" |
| 126 | + }, |
99 | 127 | { |
100 | 128 | "id": "647daefa-b9e7-33af-a399-679694464c75", |
101 | 129 | "product": { |
|
138 | 166 | }, |
139 | 167 | "product_version": "patch: 0:3.5.3-9.el9_7" |
140 | 168 | }, |
| 169 | + { |
| 170 | + "id": "943c4a1e-a069-3b5a-9c91-af630c979b43", |
| 171 | + "product": { |
| 172 | + "name": "RHEL-8 based Middleware Containers" |
| 173 | + }, |
| 174 | + "product_version": "patch: 7.13.5-4.1777325677" |
| 175 | + }, |
141 | 176 | { |
142 | 177 | "id": "94e13645-338b-32d0-8812-b0ca13380273", |
143 | 178 | "product": { |
144 | 179 | "name": "Red Hat Update Infrastructure 5" |
145 | 180 | }, |
146 | 181 | "product_version": "patch: 1776868842" |
147 | 182 | }, |
| 183 | + { |
| 184 | + "id": "95367dd3-a7da-3995-b486-0643ef8612de", |
| 185 | + "product": { |
| 186 | + "name": "RHEL-8 based Middleware Containers" |
| 187 | + }, |
| 188 | + "product_version": "patch: 7.13.5-4.1777325711" |
| 189 | + }, |
| 190 | + { |
| 191 | + "id": "98de134e-89b9-3f00-86ec-aa90e54f5e90", |
| 192 | + "product": { |
| 193 | + "name": "RHEL-8 based Middleware Containers" |
| 194 | + }, |
| 195 | + "product_version": "patch: 7.13.5-4.1777325709" |
| 196 | + }, |
| 197 | + { |
| 198 | + "id": "9b5a3298-6df0-3d4d-b9c3-8e4e5a5b4762", |
| 199 | + "product": { |
| 200 | + "name": "Red Hat Discovery 2" |
| 201 | + }, |
| 202 | + "product_version": "patch: 1778156756" |
| 203 | + }, |
148 | 204 | { |
149 | 205 | "id": "9ca3ac2a-1a76-3a25-874b-9739d1817b60", |
150 | 206 | "product": { |
|
194 | 250 | }, |
195 | 251 | "product_version": "patch: 1776868772" |
196 | 252 | }, |
| 253 | + { |
| 254 | + "id": "d007452d-73eb-3e33-bc5c-0520289039be", |
| 255 | + "product": { |
| 256 | + "name": "RHEL-8 based Middleware Containers" |
| 257 | + }, |
| 258 | + "product_version": "patch: 7.13.5-4.1777325680" |
| 259 | + }, |
| 260 | + { |
| 261 | + "id": "d1f159c0-b6a6-34f3-a308-c8cef58a53d1", |
| 262 | + "product": { |
| 263 | + "name": "Red Hat OpenShift Container Platform 4.12" |
| 264 | + }, |
| 265 | + "product_version": "patch: 412.86.202604281506-0" |
| 266 | + }, |
197 | 267 | { |
198 | 268 | "id": "d6600a3f-bd85-3e67-9243-d349fc0f5af9", |
199 | 269 | "product": { |
|
0 commit comments