PT-2026-53819 · Unknown+3 · Libarchive+3

·

CVE-2026-14164

·

Published

2026-06-30

·

Updated

2026-09-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libarchive (affected versions not specified)
Description A double free issue exists in the RAR5 reader of libarchive. When parsing a specially crafted RAR5 archive, the filtered buf pointer may remain stale after being freed during the reinitialization of the unpacking state. If another archive entry is processed, the same memory region may be freed again. This condition can cause applications utilizing the libarchive API to terminate unexpectedly, resulting in a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:52674
ALSA-2026:52675
AZL-91713
CVE-2026-14164
ECHO-54DD-0906-DC9A
OESA-2026-2887
OESA-2026-2888
OESA-2026-2889
OESA-2026-2890
OESA-2026-3040
RHSA-2026:30333
RHSA-2026:52674
RHSA-2026:52675
RHSA-2026:56954
RHSA-2026:58558
RHSA-2026:58573
RHSA-2026:58574
USN-8581-1

Affected Products

Linuxmint
Rocky Linux
Ubuntu
Libarchive