CVE-2026-14164

Summary

A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.

Affected Software

VendorProductVersion RangeStatus
Red HatRed Hat Enterprise Linux 100:3.7.7-10.el10_2 < *unaffected
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support0:3.7.7-5.el10_0.1 < *unaffected
Red HatRed Hat Enterprise Linux 90:3.5.3-11.el9_8 < *unaffected
Red HatRed Hat Enterprise Linux 90:3.5.3-11.el9_8 < *unaffected
Red HatRed Hat OpenShift Container Platform 4.224.22.9.8.202608130832-0 < *unaffected
Red HatRed Hat Discovery 21786638573 < *unaffected
Red HatRed Hat Hardened Images3.8.8-2.hum1 < *unaffected
Red HatRed Hat Update Infrastructure 51786435241 < *unaffected
Red HatRed Hat Update Infrastructure 51786533457 < *unaffected
Red HatRed Hat Update Infrastructure 51786533449 < *unaffected
Red HatRed Hat Update Infrastructure 51786435483 < *unaffected
Red HatRed Hat Update Infrastructure 51786533529 < *unaffected

Weaknesses

  • CWE-415: Double Free

Workarounds

No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the appropriate security update once it becomes available.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

Additional References

References