Junglewise Threat Intelligence

CVE-2026-14164: libarchive double free in RAR5 reader

CVE-2026-14164 · Severity: high · CVSS 7.5 · Published 2026-06-30

Technologies: Red Hat Enterprise Linux 9, Libarchive, Red Hat Enterprise Linux 10. Vendors: Red Hat, Libarchive.

Executive brief

libarchive is a widely used software library for reading and writing various compressed file formats. A flaw in how it handles RAR5 archives allows an attacker to provide a specially crafted file that causes the application using libarchive to crash. This can lead to a denial-of-service, impacting the availability of services that automatically process or scan uploaded archive files.

Technical details

A double-free vulnerability exists in libarchive's RAR5 reader subsystem within `archive_read_support_format_rar5.c`. The issue is caused by a dangling pointer, `rar->cstate.filtered_buf`, which is not nullified after being released during unpacking state reinitialization (specifically in `init_unpack` if a memory allocation fails). An attacker can provide a crafted RAR5 archive that triggers a second free operation on the same memory address during subsequent processing. This results in a memory-manager abort and application crash. A fix has been merged into the libarchive master branch.

Affected products

  • libarchive libarchive All versions prior to the fix in master branch (May 2026)
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Hardened Images

Timeline

  • 2026-05-24: patched: Fix merged into libarchive master branch via Pull Request 3071
  • 2026-06-26: disclosed: Reported to Red Hat Bugzilla
  • 2026-06-30: advisory: CVE-2026-14164 published

References

Related threats