CVE-2026-5121
published 2026-03-30CVE-2026-5121: A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can…
PriorityP352high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.07%
61.1th percentile
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libarchive | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
| ubuntu | libarchive | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2026-05-21·CVSS 7.5
CVE-2026-4426 [HIGH] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: Several security issues were fixed in libarchive.
It was discovered that libarchive incorrectly handled certain RAR
archives. An attacker could possibly use this issue to cause an
out-of-bounds read via a crafted RAR archive, leading to sensitive
memory disclosure. (CVE-2026-4424)
It was discovered that libarchive incorrectly handled certain ISO files.
An attacker could possibly use this issue to cause incorrect memory
allocation via a crafted ISO file, leading to a denial of service.
(CVE-2026-4426)
It was discovered that libarchive incorrectly handled block pointer
allocation in zisofs on 32-bit systems. An attacker could possibly use
this issue to cause a heap buffer overflow via a crafted ISO9660 image,
possibly leading to arbitrary code e
Red Hat
CVE-2026-5121: A flaw was found in libarchive
vendor_redhat·2026-03-30·CVSS 9.8
CVE-2026-5121 [CRITICAL] CVE-2026-5121: A flaw was found in libarchive
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
Statement: Important: An integer overflow flaw in `libarchive` on 32-bit systems can lead to a heap buffer o
Debian
CVE-2026-5121: libarchive - A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerabi...
vendor_debian·2026·CVSS 9.8
CVE-2026-5121 [CRITICAL] CVE-2026-5121: libarchive - A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerabi...
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Citrix
Citrix Security Bulletin CTX117751
vendor_citrix·CVSS 7.2
CVE-2008-5121 [HIGH] Citrix Security Bulletin CTX117751
Citrix Security Bulletin CTX117751
CVE References: CVE-2008-5121, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
VulDB
libarchive on 32-bit ISO9660 Image Parser heap-based overflow (EUVD-2026-17073 / Nessus ID 306774)
vuldb·2026-05-06·CVSS 7.5
CVE-2026-5121 [HIGH] libarchive on 32-bit ISO9660 Image Parser heap-based overflow (EUVD-2026-17073 / Nessus ID 306774)
A vulnerability, which was classified as critical, has been found in libarchive on 32-bit. This vulnerability affects unknown code of the component ISO9660 Image Parser. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is cataloged as CVE-2026-5121. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
GHSA
GHSA-2vwv-vqpv-v8vc: A flaw was found in libarchive
ghsa_unreviewed·2026-03-30
CVE-2026-5121 [CRITICAL] CWE-190 GHSA-2vwv-vqpv-v8vc: A flaw was found in libarchive
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
OSV
CVE-2026-5121: A flaw was found in libarchive
osv·2026-03-30·CVSS 9.8
CVE-2026-5121 [CRITICAL] CVE-2026-5121: A flaw was found in libarchive
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-5121 libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing [fedora-all]
bugzilla·2026-03-30·CVSS 9.8
CVE-2026-5121 [CRITICAL] CVE-2026-5121 libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing [fedora-all]
CVE-2026-5121 libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
---
FEDORA-2026-54ce3fd147 (libarchive-3.8.7-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-54ce3fd147
Bugzilla
CVE-2026-5121 libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing
bugzilla·2026-03-30·CVSS 9.8
CVE-2026-5121 [CRITICAL] CVE-2026-5121 libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing
CVE-2026-5121 libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing
On 32-bit systems, an integer overflow in the zisofs block pointer allocation logic (archive_read_support_format_iso9660.c, line 1537) wraps the allocation size to zero. malloc(0) returns a ~16-byte buffer, but the code records the un-wrapped size (~4 GB) and proceeds to memcpy() attacker-controlled ISO data into the tiny buffer - a heap buffer overflow WRITE. On 64-bit systems the overflow doesn't wrap and malloc fails safely. Shares root cause with vulnerability #2 (unvalidated pz_log2_bs).Requirements to exploit: The target must be a 32-bit system processing a crafted ISO9660 image via libarchive. The attacker needs to deliver the ISO to an application that extracts or reads
Wiz
CVE-2026-5121 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-5121 [MEDIUM] CVE-2026-5121 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5121 :
Linux Debian vulnerability analysis and mitigation
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
Source : NVD
## 9.8
Score
Published March 30, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
Linux Debian
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 47.5
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
bsdtar
libarchive
So
https://access.redhat.com/errata/RHSA-2026:10065https://access.redhat.com/errata/RHSA-2026:10097https://access.redhat.com/errata/RHSA-2026:11768https://access.redhat.com/errata/RHSA-2026:12071https://access.redhat.com/errata/RHSA-2026:12274https://access.redhat.com/errata/RHSA-2026:13812https://access.redhat.com/errata/RHSA-2026:14773https://access.redhat.com/errata/RHSA-2026:14937https://access.redhat.com/errata/RHSA-2026:15087https://access.redhat.com/errata/RHSA-2026:16008https://access.redhat.com/errata/RHSA-2026:16009https://access.redhat.com/errata/RHSA-2026:16030https://access.redhat.com/errata/RHSA-2026:16174https://access.redhat.com/errata/RHSA-2026:17596https://access.redhat.com/errata/RHSA-2026:19724https://access.redhat.com/errata/RHSA-2026:19725https://access.redhat.com/errata/RHSA-2026:20040https://access.redhat.com/errata/RHSA-2026:21690https://access.redhat.com/errata/RHSA-2026:25096https://access.redhat.com/errata/RHSA-2026:8510https://access.redhat.com/errata/RHSA-2026:8517https://access.redhat.com/errata/RHSA-2026:8521https://access.redhat.com/errata/RHSA-2026:8534https://access.redhat.com/errata/RHSA-2026:8864https://access.redhat.com/errata/RHSA-2026:8866https://access.redhat.com/errata/RHSA-2026:8867https://access.redhat.com/errata/RHSA-2026:8873https://access.redhat.com/errata/RHSA-2026:8908https://access.redhat.com/errata/RHSA-2026:8944https://access.redhat.com/errata/RHSA-2026:9026https://access.redhat.com/errata/RHSA-2026:9592https://access.redhat.com/errata/RHSA-2026:9832https://access.redhat.com/security/cve/CVE-2026-5121https://bugzilla.redhat.com/show_bug.cgi?id=2452945https://github.com/advisories/GHSA-2vwv-vqpv-v8vchttps://github.com/libarchive/libarchive/pull/2934https://cert-portal.siemens.com/productcert/html/ssa-585531.html
2026-03-30
Published