CVE-2024-26256Heap-based Buffer Overflow in Libarchive

Severity
7.8HIGHCNA
No vector
EPSS
41.3%
top 2.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9
Latest updateJun 4

Description

Libarchive Remote Code Execution Vulnerability Libarchive Remote Code Execution Vulnerability

Affected Packages9 packages

debiandebian/libarchive< libarchive 3.6.2-1+deb12u1 (bookworm)
CVEListV5microsoft/windows_11_version_22h210.0.22621.010.0.22621.3447
CVEListV5microsoft/windows_11_version_22h310.0.22631.010.0.22631.3447
CVEListV5microsoft/windows_11_version_23h210.0.22631.010.0.22631.3447

🔴Vulnerability Details

1
CVEList
Libarchive Remote Code Execution Vulnerability2024-04-09

📋Vendor Advisories

5
Ubuntu
libarchive vulnerability2024-06-04
Microsoft
Libarchive Remote Code Execution Vulnerability2024-04-09
Red Hat
libarchive: Heap based buffer overflow in rar e8 filter2024-04-09
Red Hat
libarchive: Heap based buffer overflow in rar e8 filter2024-01-09
Debian
CVE-2024-26256: libarchive - Libarchive Remote Code Execution Vulnerability2024

🕵️Threat Intelligence

5
Qualys
Microsoft and Adobe Patch Tuesday, April 2024 Security Update Review2024-04-09
Trendmicro
The April 2024 Security Updates Review2024-04-09
Bleepingcomputer
Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs2024-04-09
Trendmicro
The April 2024 Security Updates Review2024-04-09
Qualys
Security Update Review: Microsoft & Adobe April 2024 Patch Tuesday | Qualys2024-04-09
CVE-2024-26256 — Heap-based Buffer Overflow | cvebase