CVE-2026-5745
published 2026-04-07CVE-2026-5745: A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl()…
PriorityP421medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.16%
5.9th percentile
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libarchive | — | — |
| linux | linux_kernel | >= 6.18.0 < 6.18.6 | 6.18.6 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_redhat7.6MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libarchive: A NULL pointer dereference vulnerability exists in the ACL parser of libarchive
vendor_redhat·2026-04-07·CVSS 5.5
CVE-2026-5745 [MEDIUM] CWE-476 libarchive: A NULL pointer dereference vulnerability exists in the ACL parser of libarchive
libarchive: A NULL pointer dereference vulnerability exists in the ACL parser of libarchive
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).
Statement: This Moderate impact vulnerability in libarchive's ACL parsing logic can lead to a Denial of Service. An attacker could provide a specially crafted arch
Red Hat
kernel: wifi: mac80211_hwsim: fix typo in frequency notification
vendor_redhat·2026-02-04·CVSS 7.6
CVE-2026-23040 [MEDIUM] CWE-476 kernel: wifi: mac80211_hwsim: fix typo in frequency notification
kernel: wifi: mac80211_hwsim: fix typo in frequency notification
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: fix typo in frequency notification
The NAN notification is for 5745 MHz which corresponds to channel 149
and not 5475 which is not actually a valid channel. This could result in
a NULL pointer dereference in cfg80211_next_nan_dw_notif.
Statement: The mac80211_hwsim virtual WiFi driver contains an incorrect frequency constant used when generating NAN discovery window notifications on the 5 GHz band that can lead to Null pointer deref. In mac80211_hwsim_nan_dw_start the driver calls ieee80211_get_channel with 5475 MHz when nan_curr_dw_band is NL80211_BAND_5GHZ. That frequency does not correspond to a valid channel in typical wiphy channe
Debian
CVE-2026-5745: libarchive - A flaw was found in libarchive. A NULL pointer dereference vulnerability exists ...
vendor_debian·2026·CVSS 5.5
CVE-2026-5745 [MEDIUM] CVE-2026-5745: libarchive - A flaw was found in libarchive. A NULL pointer dereference vulnerability exists ...
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
CVE-2026-5745: A flaw was found in libarchive
osv·2026-04-07·CVSS 5.5
CVE-2026-5745 [MEDIUM] CVE-2026-5745: A flaw was found in libarchive
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).
GHSA
GHSA-fjqv-vj6q-4fcm: A flaw was found in libarchive
ghsa_unreviewed·2026-04-07
CVE-2026-5745 [MEDIUM] CWE-476 GHSA-fjqv-vj6q-4fcm: A flaw was found in libarchive
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).
OSV
wifi: mac80211_hwsim: fix typo in frequency notification
osv·2026-02-04
CVE-2026-23040 wifi: mac80211_hwsim: fix typo in frequency notification
wifi: mac80211_hwsim: fix typo in frequency notification
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: fix typo in frequency notification
The NAN notification is for 5745 MHz which corresponds to channel 149
and not 5475 which is not actually a valid channel. This could result in
a NULL pointer dereference in cfg80211_next_nan_dw_notif.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-5745 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.0
CVE-2026-5745 [CRITICAL] CVE-2026-5745 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5745 :
Linux Debian vulnerability analysis and mitigation
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).
Source : NVD
## 5.5
Score
Published April 7, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Linux Debian
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit
Bugzilla
CVE-2026-5745 libarchive: A NULL pointer dereference vulnerability exists in the ACL parser of libarchive
bugzilla·2026-04-07·CVSS 5.5
CVE-2026-5745 [MEDIUM] CVE-2026-5745 libarchive: A NULL pointer dereference vulnerability exists in the ACL parser of libarchive
CVE-2026-5745 libarchive: A NULL pointer dereference vulnerability exists in the ACL parser of libarchive
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).
Bugzilla
CVE-2026-23040 kernel: wifi: mac80211_hwsim: fix typo in frequency notification
bugzilla·2026-02-04
CVE-2026-23040 [MEDIUM] CVE-2026-23040 kernel: wifi: mac80211_hwsim: fix typo in frequency notification
CVE-2026-23040 kernel: wifi: mac80211_hwsim: fix typo in frequency notification
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: fix typo in frequency notification
The NAN notification is for 5745 MHz which corresponds to channel 149
and not 5475 which is not actually a valid channel. This could result in
a NULL pointer dereference in cfg80211_next_nan_dw_notif.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026020438-CVE-2026-23040-1980@gregkh/T
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:18134 https://access.redhat.com/errata/RHSA-2026:18134
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:18587 h
2026-04-07
Published