Executive brief
YARA is a pattern matching tool used to identify and classify malware and security incidents. A flaw in how YARA processes compiled rule files (.yrc) allows an attacker to provide a malicious file that causes the application to crash with an assertion failure, creating a denial of service. This affects systems that automatically load untrusted compiled rules, such as security scanning infrastructure.
Technical details
A reachable assertion (CWE-617) exists in yr_arena_get_ptr() when loading .yrc files with an invalid arena buffer count (num_buffers=0). The yr_arena_load_stream() function accepts zero buffers during file loading, but yr_rules_from_arena() unconditionally accesses the first buffer to read metadata, triggering an assertion failure in assert-enabled builds. The flaw is reachable via the public yr_rules_load_stream API used by the yara CLI and causes SIGABRT in debug/test builds; NDEBUG production builds degrade gracefully to an error.
Affected products
- VirusTotal YARA 4.5.8
Timeline
- 2026-09-22: disclosed
- 2026-08-25: patched: Fix committed to validate arena buffer count