CVE-2026-4426
published 2026-03-19CVE-2026-4426: A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.30%
22.8th percentile
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libarchive | — | — |
| msrc | azl3_libarchive_3.7.7-4_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libarchive_3.6.1-8_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
| ubuntu | libarchive | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2026-05-21·CVSS 7.5
CVE-2026-4426 [HIGH] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: Several security issues were fixed in libarchive.
It was discovered that libarchive incorrectly handled certain RAR
archives. An attacker could possibly use this issue to cause an
out-of-bounds read via a crafted RAR archive, leading to sensitive
memory disclosure. (CVE-2026-4424)
It was discovered that libarchive incorrectly handled certain ISO files.
An attacker could possibly use this issue to cause incorrect memory
allocation via a crafted ISO file, leading to a denial of service.
(CVE-2026-4426)
It was discovered that libarchive incorrectly handled block pointer
allocation in zisofs on 32-bit systems. An attacker could possibly use
this issue to cause a heap buffer overflow via a crafted ISO9660 image,
possibly leading to arbitrary code e
Red Hat
libarchive: libarchive: Denial of Service via malformed ISO file processing
vendor_redhat·2026-03-19·CVSS 6.5
CVE-2026-4426 [MEDIUM] CWE-1335 libarchive: libarchive: Denial of Service via malformed ISO file processing
libarchive: libarchive: Denial of Service via malformed ISO file processing
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incor
Microsoft
Libarchive: libarchive: denial of service via malformed iso file processing
vendor_msrc·2026-03-10·CVSS 6.5
CVE-2026-4426 [MEDIUM] CWE-1335 Libarchive: libarchive: denial of service via malformed iso file processing
Libarchive: libarchive: denial of service via malformed iso file processing
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Debian
CVE-2026-4426: libarchive - A flaw was found in libarchive. An Undefined Behavior vulnerability exists in th...
vendor_debian·2026·CVSS 6.5
CVE-2026-4426 [MEDIUM] CVE-2026-4426: libarchive - A flaw was found in libarchive. An Undefined Behavior vulnerability exists in th...
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-r3fp-vrpw-pg77: A flaw was found in libarchive
ghsa_unreviewed·2026-03-19
CVE-2026-4426 [MEDIUM] CWE-1335 GHSA-r3fp-vrpw-pg77: A flaw was found in libarchive
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.
OSV
CVE-2026-4426: A flaw was found in libarchive
osv·2026-03-19·CVSS 6.5
CVE-2026-4426 [MEDIUM] CVE-2026-4426: A flaw was found in libarchive
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-4426 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-4426 [MEDIUM] CVE-2026-4426 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4426 :
Linux Debian vulnerability analysis and mitigation
pz_log2_bs
Source : NVD
## 6.5
Score
Published March 19, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 31.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
bsdtar
libarchive-devel
Sources
NVD
Debian 11, 12, 13, 14 Severity MEDIUM No Fix Added at: Mar 20, 2026
Echo Severity MEDIUM No Fix Added at: Mar 20, 2026
Red Hat 6, 7, 8, 9, 10 Severity MEDIUM No Fix Added at: Mar 20, 2026
Red Hat 8 Severity MEDIUM Has Fix Added at: Mar 21, 2026
Ubuntu 16.04, 18.04, 20.04, 22.04, 24.04, 25.10 Severity MEDIUM No Fix
Bugzilla
CVE-2026-4426 libarchive: libarchive: Denial of Service via malformed ISO file processing [fedora-all]
bugzilla·2026-03-19·CVSS 6.5
CVE-2026-4426 [MEDIUM] CVE-2026-4426 libarchive: libarchive: Denial of Service via malformed ISO file processing [fedora-all]
CVE-2026-4426 libarchive: libarchive: Denial of Service via malformed ISO file processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
---
FEDORA-2026-54ce3fd147 (libarchive-3.8.7-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-54ce3fd147
Bugzilla
CVE-2026-4426 libarchive: libarchive: Denial of Service via malformed ISO file processing
bugzilla·2026-03-19·CVSS 6.5
CVE-2026-4426 [MEDIUM] CVE-2026-4426 libarchive: libarchive: Denial of Service via malformed ISO file processing
CVE-2026-4426 libarchive: libarchive: Denial of Service via malformed ISO file processing
An Undefined Behavior vulnerability exists in the zisofs decompression logic of the libarchive library. The flaw is caused by improper validation of the pz_log2_bs field, which is directly read from ISO9660 Rock Ridge extensions and used as a shift exponent in arithmetic operations. When a specially crafted ISO file provides an out-of-range value (e.g., ≥64 on 64-bit systems), it triggers undefined behavior due to invalid shift operations, leading to incorrect memory allocation and potential crashes. This vulnerability can be exploited by supplying a malicious ISO file, resulting in denial-of-service conditions in applications that process ISO images.
2026-03-19
Published