Junglewise Threat Intelligence

CVE-2026-6676: Avira Antivirus heap out-of-bounds write in POSIX tar scanning

CVE-2026-6676 · Severity: high · CVSS 7.8 · Published 2026-06-12

Vendors: Avira.

Executive brief

Avira Antivirus is a security suite used to protect computers from malware and cyber threats. A vulnerability in its scanning engine could allow a malicious file to crash the antivirus software or potentially run unauthorized code on the system. This occurs when the software attempts to scan a specially crafted archive file, potentially leading to a loss of protection or full system compromise.

Technical details

A heap-based out-of-bounds write vulnerability (CWE-787) exists in the Avira Antivirus engine's handling of POSIX tar archives. The flaw is triggered when the engine parses a malformed archive during a scan, leading to memory corruption. While the attack vector is classified as local, it requires a user to interact with a malicious file (UI:R), such as downloading or opening a crafted tar archive that the engine then scans. Successful exploitation can result in the execution of arbitrary code with the privileges of the antivirus process or a denial-of-service (DoS) by crashing the engine. The issue is resolved in engine builds 8.3.27.12 and later across Windows, macOS, and Linux platforms.

Affected products

  • Avira Antivirus Engine builds before 8.3.27.12

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory

References