Junglewise Threat Intelligence

CVE-2026-88341: YARA reachable assertion in arena buffer loading

CVE-2026-88341 · Severity: medium · CVSS 5.5 · Published 2026-09-22

Executive brief

YARA is a pattern matching tool used to identify and classify malware and security incidents. A flaw in how YARA processes compiled rule files (.yrc) allows an attacker to provide a malicious file that causes the application to crash with an assertion failure, creating a denial of service. This affects systems that automatically load untrusted compiled rules, such as security scanning infrastructure.

Technical details

A reachable assertion (CWE-617) exists in yr_arena_get_ptr() when loading .yrc files with an invalid arena buffer count (num_buffers=0). The yr_arena_load_stream() function accepts zero buffers during file loading, but yr_rules_from_arena() unconditionally accesses the first buffer to read metadata, triggering an assertion failure in assert-enabled builds. The flaw is reachable via the public yr_rules_load_stream API used by the yara CLI and causes SIGABRT in debug/test builds; NDEBUG production builds degrade gracefully to an error.

Affected products

  • VirusTotal YARA 4.5.8

Timeline

  • 2026-09-22: disclosed
  • 2026-08-25: patched: Fix committed to validate arena buffer count

References

Related threats