← back
CVE-2024-26256highCWE-122

Libarchive Remote Code Execution Vulnerability

43Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.8epss 88%
exploitation probability
88%top 1% of all CVEs
observed exploitation
nono source reports it
In short

Libarchive, a library used to extract files from compressed archives, has a vulnerability that allows attackers to run malicious code on your computer by crafting a specially designed archive file. When you extract this malicious archive, the attacker's code executes with the same privileges as your application.

Technical detail

A buffer overflow vulnerability (CWE-122) in libarchive's archive extraction routine allows remote code execution when processing specially crafted archive files. The attack vector requires user interaction to extract a malicious archive; successful exploitation grants arbitrary code execution in the context of the vulnerable application.

Summary generated and translated by AI from the official description.
Libarchive Remote Code Execution Vulnerability
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C