CVE-2026-5121

A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
References
Link Resource
https://access.redhat.com/errata/RHSA-2026:10065
https://access.redhat.com/errata/RHSA-2026:10097
https://access.redhat.com/errata/RHSA-2026:11768
https://access.redhat.com/errata/RHSA-2026:12071
https://access.redhat.com/errata/RHSA-2026:12274
https://access.redhat.com/errata/RHSA-2026:13812
https://access.redhat.com/errata/RHSA-2026:14773
https://access.redhat.com/errata/RHSA-2026:14937
https://access.redhat.com/errata/RHSA-2026:15087
https://access.redhat.com/errata/RHSA-2026:16008
https://access.redhat.com/errata/RHSA-2026:16009
https://access.redhat.com/errata/RHSA-2026:16030
https://access.redhat.com/errata/RHSA-2026:16174
https://access.redhat.com/errata/RHSA-2026:17596
https://access.redhat.com/errata/RHSA-2026:19724
https://access.redhat.com/errata/RHSA-2026:19725
https://access.redhat.com/errata/RHSA-2026:20040
https://access.redhat.com/errata/RHSA-2026:21690
https://access.redhat.com/errata/RHSA-2026:25096
https://access.redhat.com/errata/RHSA-2026:8510
https://access.redhat.com/errata/RHSA-2026:8517
https://access.redhat.com/errata/RHSA-2026:8521
https://access.redhat.com/errata/RHSA-2026:8534
https://access.redhat.com/errata/RHSA-2026:8864
https://access.redhat.com/errata/RHSA-2026:8866
https://access.redhat.com/errata/RHSA-2026:8867
https://access.redhat.com/errata/RHSA-2026:8873
https://access.redhat.com/errata/RHSA-2026:8908
https://access.redhat.com/errata/RHSA-2026:8944
https://access.redhat.com/errata/RHSA-2026:9026
https://access.redhat.com/errata/RHSA-2026:9592
https://access.redhat.com/errata/RHSA-2026:9832
https://access.redhat.com/security/cve/CVE-2026-5121 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2452945
https://github.com/advisories/GHSA-2vwv-vqpv-v8vc Third Party Advisory
https://github.com/libarchive/libarchive/pull/2934 Issue Tracking Patch
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libarchive:libarchive:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

10 Jun 2026, 18:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:25096 -

04 Jun 2026, 19:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:21690 -

28 May 2026, 03:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:20040 -

21 May 2026, 04:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:19724 -

20 May 2026, 17:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:17596 -
  • () https://access.redhat.com/errata/RHSA-2026:19725 -

14 May 2026, 23:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:16008 -
  • () https://access.redhat.com/errata/RHSA-2026:16009 -
  • () https://access.redhat.com/errata/RHSA-2026:16030 -

13 May 2026, 16:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:14773 -
  • () https://access.redhat.com/errata/RHSA-2026:15087 -

12 May 2026, 10:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:16174 -

11 May 2026, 10:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:12071 -

09 May 2026, 00:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:12274 -

07 May 2026, 22:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:14937 -

05 May 2026, 18:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:13812 -

30 Apr 2026, 14:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:10097 -
  • () https://access.redhat.com/errata/RHSA-2026:11768 -
  • () https://access.redhat.com/errata/RHSA-2026:8944 -

23 Apr 2026, 07:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:10065 -

22 Apr 2026, 18:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:9832 -

22 Apr 2026, 07:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:9592 -

20 Apr 2026, 14:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:9026 -

20 Apr 2026, 09:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:8866 -

20 Apr 2026, 06:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:8908 -

20 Apr 2026, 05:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:8873 -

20 Apr 2026, 04:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:8864 -

20 Apr 2026, 03:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:8867 -

16 Apr 2026, 20:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:8517 -
  • () https://access.redhat.com/errata/RHSA-2026:8521 -

16 Apr 2026, 19:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:8534 -

16 Apr 2026, 17:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:8510 -

14 Apr 2026, 17:16

Type Values Removed Values Added
References
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2452945 -

14 Apr 2026, 16:36

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2026-5121 - () https://access.redhat.com/security/cve/CVE-2026-5121 - Third Party Advisory
References () https://github.com/advisories/GHSA-2vwv-vqpv-v8vc - () https://github.com/advisories/GHSA-2vwv-vqpv-v8vc - Third Party Advisory
References () https://github.com/libarchive/libarchive/pull/2934 - () https://github.com/libarchive/libarchive/pull/2934 - Issue Tracking, Patch
First Time Redhat
Redhat enterprise Linux
Libarchive libarchive
Libarchive
Redhat hardened Images
Redhat openshift Container Platform
CPE cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:libarchive:libarchive:-:*:*:*:*:*:*:*

14 Apr 2026, 16:16

Type Values Removed Values Added
Summary
  • (es) Se encontró un fallo en libarchive. En sistemas de 32 bits, existe una vulnerabilidad de desbordamiento de entero en la lógica de asignación de punteros de bloque zisofs. Un atacante remoto puede explotar esto al proporcionar una imagen ISO9660 especialmente diseñada, lo que puede llevar a un desbordamiento de búfer de pila. Esto podría permitir potencialmente la ejecución de código arbitrario en el sistema afectado.
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 7.5
References
  • () https://github.com/advisories/GHSA-2vwv-vqpv-v8vc -

31 Mar 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-190

30 Mar 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 08:16

Updated : 2026-06-10 18:17


NVD link : CVE-2026-5121

Mitre link : CVE-2026-5121

CVE.ORG link : CVE-2026-5121


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • hardened_images
  • openshift_container_platform

libarchive

  • libarchive
CWE
CWE-190

Integer Overflow or Wraparound