Security Advisory

CVE-2026-4426

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-03-19 13:53:39
Last updated 2026-05-03 20:57:03
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.