Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-14164— Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack()

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

libarchive是libarchive团队开源的一款多格式存档和压缩库。 libarchive存在资源管理错误漏洞,该漏洞源于RAR5解析器中的双重释放问题,在解析特制RAR5存档时,filtered_buf指针在解压状态重新初始化释放后可能未重置,后续处理另一个归档条目时可能导致同一内存区域被二次释放,成功利用可能导致使用易受攻击的libarchive API的应用程序意外终止,导致拒绝服务。

CVSS 7.5 · High EPSS 0.73% · P53

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 53

VendorProduct Version RangeStatus
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790223279< * unaffected
1790223719< * unaffected
1790272426< * unaffected
1790589998< * unaffected
1790589912< * unaffected
1790589914< * unaffected
1790589855< * unaffected
1790598593< * unaffected
Red Hat Red Hat Discovery 2 1786638573< * unaffected
1788206196< * unaffected
Red Hat Red Hat Enterprise Linux 10 0:3.7.7-10.el10_2< * unaffected
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support 0:3.7.7-5.el10_0.1< * unaffected
Red Hat Red Hat Enterprise Linux 6 any unaffected
Red Hat Red Hat Enterprise Linux 7 any unaffected
Red Hat Red Hat Enterprise Linux 8 any unaffected
Red Hat Red Hat Enterprise Linux 9 0:3.5.3-11.el9_8< * unaffected
0:3.5.3-11.el9_8< * unaffected
Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions 0:3.5.3-5.el9_2.3< * unaffected
Red Hat Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 0:3.5.3-5.el9_4.2< * unaffected
Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support 0:3.5.3-7.el9_6.2< * unaffected
Red Hat Red Hat Hardened Images 3.8.8-2.hum1< * unaffected
Red Hat Red Hat OpenShift AI 3.0 1790276886< * unaffected
1790276884< * unaffected
1790277045< * unaffected
1790276889< * unaffected
1790276974< * unaffected
Red Hat Red Hat OpenShift AI 3.2 1790703497< * unaffected
1790703506< * unaffected
1790703590< * unaffected
1790703568< * unaffected
1790703586< * unaffected
1790703494< * unaffected
Red Hat Red Hat OpenShift AI 3.4 1790703542< * unaffected
Red Hat Red Hat OpenShift Container Platform 4 any unaffected
Red Hat Red Hat OpenShift Container Platform 4.13 413.92.202609080414-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.14 414.92.202609011250-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.15 415.92.202609140326-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.16 416.94.202609140240-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.17 417.94.202609191027-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.18 418.94.202609031320-0< * unaffected
418.94.202609171815-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.19 4.19.9.6.202609021231-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.20 4.20.9.6.202609021029-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.21 4.21.9.6.202609021100-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.22 4.22.9.8.202608130832-0< * unaffected
Red Hat Red Hat Update Infrastructure 5 1786435241< * unaffected
1786533457< * unaffected
1786533449< * unaffected
1786435483< * unaffected
1786533529< * unaffected
1787241211< * unaffected
1787135742< * unaffected
1787241260< * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-14164

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack()
Source: CVE Program / CVE List V5
Vulnerability Description
A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
双重释放
Source: CVE Program / CVE List V5
Vulnerability Title
libarchive 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
libarchive是libarchive团队开源的一款多格式存档和压缩库。 libarchive存在资源管理错误漏洞,该漏洞源于RAR5解析器中的双重释放问题,在解析特制RAR5存档时,filtered_buf指针在解压状态重新初始化释放后可能未重置,后续处理另一个归档条目时可能导致同一内存区域被二次释放,成功利用可能导致使用易受攻击的libarchive API的应用程序意外终止,导致拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 0:3.7.7-10.el10_2 ~ * cpe:/o:redhat:enterprise_linux:10.2
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support 0:3.7.7-5.el10_0.1 ~ * cpe:/o:redhat:enterprise_linux_eus:10.0
Red Hat Red Hat Enterprise Linux 9 0:3.5.3-11.el9_8 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:3.5.3-11.el9_8 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions 0:3.5.3-5.el9_2.3 ~ * cpe:/a:redhat:rhel_e4s:9.2::appstream
Red Hat Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 0:3.5.3-5.el9_4.2 ~ * cpe:/a:redhat:rhel_e4s:9.4::appstream
Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support 0:3.5.3-7.el9_6.2 ~ * cpe:/a:redhat:rhel_eus:9.6::appstream
Red Hat Red Hat OpenShift Container Platform 4.13 413.92.202609080414-0 ~ * cpe:/a:redhat:openshift:4.13::el9
Red Hat Red Hat OpenShift Container Platform 4.14 414.92.202609011250-0 ~ * cpe:/a:redhat:openshift:4.14::el9
Red Hat Red Hat OpenShift Container Platform 4.15 415.92.202609140326-0 ~ * cpe:/a:redhat:openshift:4.15::el9
Red Hat Red Hat OpenShift Container Platform 4.16 416.94.202609140240-0 ~ * cpe:/a:redhat:openshift:4.16::el9
Red Hat Red Hat OpenShift Container Platform 4.17 417.94.202609191027-0 ~ * cpe:/a:redhat:openshift:4.17::el9
Red Hat Red Hat OpenShift Container Platform 4.18 418.94.202609031320-0 ~ * cpe:/a:redhat:openshift:4.18::el9
Red Hat Red Hat OpenShift Container Platform 4.18 418.94.202609171815-0 ~ * cpe:/a:redhat:openshift:4.18::el9
Red Hat Red Hat OpenShift Container Platform 4.19 4.19.9.6.202609021231-0 ~ * cpe:/a:redhat:openshift:4.19::el9
Red Hat Red Hat OpenShift Container Platform 4.20 4.20.9.6.202609021029-0 ~ * cpe:/a:redhat:openshift:4.20::el9
Red Hat Red Hat OpenShift Container Platform 4.21 4.21.9.6.202609021100-0 ~ * cpe:/a:redhat:openshift:4.21::el9
Red Hat Red Hat OpenShift Container Platform 4.22 4.22.9.8.202608130832-0 ~ * cpe:/a:redhat:openshift:4.22::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790223279 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790223719 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790272426 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589998 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589912 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589914 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589855 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790598593 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Red Hat Discovery 2 1786638573 ~ * cpe:/a:redhat:discovery:2::el9
Red Hat Red Hat Discovery 2 1788206196 ~ * cpe:/a:redhat:discovery:2::el9
Red Hat Red Hat Hardened Images 3.8.8-2.hum1 ~ * cpe:/a:redhat:hummingbird:1
Red Hat Red Hat OpenShift AI 3.0 1790276886 ~ * cpe:/a:redhat:openshift_ai:3.0::el9

II. Public POCs for CVE-2026-14164

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 11896 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-14164

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-14164 (2)

Vendor Advisories for CVE-2026-14164 (42)

Same Patch Batch · Red Hat · 2026-06-30 · 6 CVEs total

CVE-2026-12388 6.5 MEDIUM Keycloak-broker: keycloak: privilege escalation to realm administrator via improper author
CVE-2026-4629 6.5 MEDIUM Keycloak: keycloak: privilege escalation through hardcoded role mapper injection
CVE-2026-12610 6.4 MEDIUM Sssd: use-after-free crash in sssd' 'sssd_pam' process
CVE-2026-13316 4.4 MEDIUM Foreman: ssrf to cloud metada service through unvalidated test_url parameters in foreman c
CVE-2026-14209 4.3 MEDIUM Keycloak-admin-ui: keycloak-admin-ui:admin ui extension brute-force-user endpoint bypasses

IV. Related Vulnerabilities

V. Comments for CVE-2026-14164

No comments yet


Leave a comment