PT-2026-97027 · Undefined · Undefined
CVE-2026-88341
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num buffers=0) that triggers an assertion failure in yr arena get ptr(), causing the application to terminate.
Exploit
Fix
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined