cbcvebase.
CVE-2024-26256
published 2024-04-09

CVE-2024-26256: Libarchive Remote Code Execution Vulnerability Libarchive Remote Code Execution Vulnerability

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
87.78%
99.7th percentile
Libarchive Remote Code Execution Vulnerability Libarchive Remote Code Execution Vulnerability

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlibarchive< libarchive 3.6.2-1+deb12u1 (bookworm)libarchive 3.6.2-1+deb12u1 (bookworm)
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.344710.0.22621.3447
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.344710.0.22631.3447
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.344710.0.22631.3447
msrcwindows_11_version_22h2_for_arm64-based_systems
msrcwindows_11_version_22h2_for_x64-based_systems
msrcwindows_11_version_23h2_for_arm64-based_systems
msrcwindows_11_version_23h2_for_x64-based_systems
msrcwindows_server_2022_23h2_edition

Detection & IOCsextracted from sources · hover to see the quote

pathlibarchive/archive_read_support_format_rar.c
  • Trigger condition is processing a specially crafted RAR archive file; monitor applications using libarchive for crashes or anomalous behavior when opening RAR files.
  • The vulnerable function is execute_filter_e8 in the RAR format reader; stack traces or crash dumps referencing this function in libarchive are indicative of exploitation attempts.
  • The vulnerability is in the RAR e8 filter code path; focus detection on libarchive-linked applications (e.g., file managers, archivers) processing RAR archives and crashing.
  • User interaction is required — the attack vector involves a user opening a malicious RAR file; monitor for unexpected process crashes in libarchive-linked applications after RAR file open events.
  • ·Red Hat Enterprise Linux 6, 7, 8, and 9 ship versions of libarchive that do NOT contain the vulnerable code; the vulnerable code was introduced in a newer version of libarchive. Detection efforts on RHEL should focus on non-default or third-party libarchive installations.
  • ·Red Hat rates this as denial-of-service only (no confirmed RCE PoC); the RCE classification is specific to the Windows context. Adjust severity scoring accordingly for Linux environments.
  • ·On Windows, the vulnerability is tracked separately as CVE-2024-20697 and affects the Windows Compressed Folder component; patched via KB5036893 and KB5036910.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvelistv57.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.