A Heap Out-of-Bounds Read vulnerability exists in the RAR archive processing logic of the libarchive library. The issue arises from improper validation of the LZSS sliding window size after transitions between compression methods (PPMd and LZSS). Due to a mismatch between the allocated buffer size and the expected dictionary size, the copy_from_lzss_window() function performs out-of-bounds memory reads. This allows a specially crafted RAR archive to leak heap memory through the archive_read_data() API before integrity checks (CRC) are enforced. The vulnerability can be exploited remotely without authentication or user interaction in systems that automatically process archives, leading to disclosure of sensitive information.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:8492 https://access.redhat.com/errata/RHSA-2026:8492
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:8510 https://access.redhat.com/errata/RHSA-2026:8510
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:8517 https://access.redhat.com/errata/RHSA-2026:8517
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:8521 https://access.redhat.com/errata/RHSA-2026:8521
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:8534 https://access.redhat.com/errata/RHSA-2026:8534
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:8867 https://access.redhat.com/errata/RHSA-2026:8867
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:8864 https://access.redhat.com/errata/RHSA-2026:8864
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:8865 https://access.redhat.com/errata/RHSA-2026:8865
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:8873 https://access.redhat.com/errata/RHSA-2026:8873
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:8866 https://access.redhat.com/errata/RHSA-2026:8866
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:8908 https://access.redhat.com/errata/RHSA-2026:8908
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:9026 https://access.redhat.com/errata/RHSA-2026:9026
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:9592 https://access.redhat.com/errata/RHSA-2026:9592
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2026:10097 https://access.redhat.com/errata/RHSA-2026:10097
This issue has been addressed in the following products: RHEL-8 based Middleware Containers Via RHSA-2026:13812 https://access.redhat.com/errata/RHSA-2026:13812
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2026:12274 https://access.redhat.com/errata/RHSA-2026:12274