Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78322— File-roller: file-roller: stack buffer overflow in parse_progress_line for 7z and rar handlers

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 6
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 file-roller 中发现了一个安全漏洞。当打开或解压包含文件条目且路径过长的恶意 7z 或 RAR 压缩文件时,file-roller 在处理进度条时会将该路径通过无界字符串拷贝操作复制到固定大小的栈缓冲区中。这可能导致栈缓冲区溢出,并使 file-roller 终止运行,从而造成拒绝服务(DoS)攻击。要利用此漏洞,攻击者需要诱使用户使用 file-roller 打开或解压精心构造的压缩文件。

CVSS 6.5 · Medium EPSS 0.28% · P20

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise

Affected Version Matrix 3

VendorProduct Version RangeStatus
Red Hat Red Hat Enterprise Linux 6 any affected
Red Hat Red Hat Enterprise Linux 7 any affected
Red Hat Red Hat Enterprise Linux 8 any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78322

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
File-roller: file-roller: stack buffer overflow in parse_progress_line for 7z and rar handlers
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a stack buffer overflow and cause file-roller to terminate, resulting in a denial of service. To exploit this flaw, a victim must open or extract the crafted archive using file-roller.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8

II. Public POCs for CVE-2026-78322

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78322

登录查看更多情报信息。

Patches & Fixes for CVE-2026-78322 (1)

Vendor Advisories for CVE-2026-78322 (2)

Other References for CVE-2026-78322 (1)

Same Patch Batch · Red Hat · 2026-08-25 · 10 CVEs total

CVE-2026-79992 7.8 HIGH Emacs: local shell command injection through the user field in emacs tramp
CVE-2026-79655 7.8 HIGH Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targ
CVE-2026-80186 7.6 HIGH Bluez: stack overflow in name2utf8 causes dos and potential code execution
CVE-2026-78701 6.5 MEDIUM 389-ds-base: 389-ds-base: cve-2026-11610 incomplete fix may introduce a connection-stall d
CVE-2026-79717 6.4 MEDIUM Galaxy_ng: galaxy_ng: blind ssrf via namespace avatar_url with no private-address restrict
CVE-2026-79652 5.9 MEDIUM Keycloak-services: keycloak-services: jwt bearer authorization grant does not enforce cons
CVE-2026-80185 5.7 MEDIUM Bluez: sdp-xml: bluez 5.86: unprivileged-local and adjacent-le-peer leads to arbitrary cod
CVE-2026-77680 5.3 MEDIUM Libsoup3: libsoup: quadratic cpu denial of service in http range coalescing after cve-2025
CVE-2026-80101 4.4 MEDIUM Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-l

IV. Related Vulnerabilities

V. Comments for CVE-2026-78322

No comments yet


Leave a comment