Executive brief
libarchive is a widely used software library for reading and writing various compressed file formats. A flaw in how it handles RAR5 archives allows an attacker to provide a specially crafted file that causes the application using libarchive to crash. This can lead to a denial-of-service, impacting the availability of services that automatically process or scan uploaded archive files.
Technical details
A double-free vulnerability exists in libarchive's RAR5 reader subsystem within `archive_read_support_format_rar5.c`. The issue is caused by a dangling pointer, `rar->cstate.filtered_buf`, which is not nullified after being released during unpacking state reinitialization (specifically in `init_unpack` if a memory allocation fails). An attacker can provide a crafted RAR5 archive that triggers a second free operation on the same memory address during subsequent processing. This results in a memory-manager abort and application crash. A fix has been merged into the libarchive master branch.
Affected products
- libarchive libarchive All versions prior to the fix in master branch (May 2026)
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Hardened Images
Timeline
- 2026-05-24: patched: Fix merged into libarchive master branch via Pull Request 3071
- 2026-06-26: disclosed: Reported to Red Hat Bugzilla
- 2026-06-30: advisory: CVE-2026-14164 published