CVE-2026-24857

`bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar code has a heap‑buffer‑overflow in the RAR PPM LZ decoding path. A crafted RAR inside a disk image causes an out‑of‑bounds write in `Unpack::CopyString`, leading to a crash under ASAN (and likely a crash or memory corruption in production builds). There's potential for using this for RCE. As of time of publication, no known patches are available.
Configurations

Configuration 1 (hide)

cpe:2.3:a:simsong:bulk_extractor:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:23

Type Values Removed Values Added
Summary
  • (es) 'bulk_extractor' es una herramienta de explotación forense digital. A partir de la versión 1.4, el código unrar incrustado de 'bulk_extractor' tiene un desbordamiento de búfer de montón en la ruta de decodificación RAR PPM LZ. Un RAR manipulado dentro de una imagen de disco causa una escritura fuera de límites en 'Unpack::CopyString', lo que lleva a un fallo bajo ASAN (y probablemente un fallo o corrupción de memoria en compilaciones de producción). Existe el potencial de usar esto para RCE. Al momento de la publicación, no hay parches conocidos disponibles.

09 Feb 2026, 16:47

Type Values Removed Values Added
References () https://github.com/simsong/bulk_extractor/security/advisories/GHSA-rh8m-9xrx-q64q - () https://github.com/simsong/bulk_extractor/security/advisories/GHSA-rh8m-9xrx-q64q - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Simsong bulk Extractor
Simsong
CPE cpe:2.3:a:simsong:bulk_extractor:*:*:*:*:*:*:*:*
CWE CWE-787

29 Jan 2026, 18:16

Type Values Removed Values Added
References () https://github.com/simsong/bulk_extractor/security/advisories/GHSA-rh8m-9xrx-q64q - () https://github.com/simsong/bulk_extractor/security/advisories/GHSA-rh8m-9xrx-q64q -

28 Jan 2026, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-28 22:15

Updated : 2026-06-17 10:23


NVD link : CVE-2026-24857

Mitre link : CVE-2026-24857

CVE.ORG link : CVE-2026-24857


JSON object : View

Products Affected

simsong

  • bulk_extractor
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write