{"id":"CVE-2026-14164","title":"A double free issue has been identified in libarchive's RAR5 reader","summary":"A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent proc…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-415"],"vendor":"Red Hat","product":"libarchive","affected":["libarchive (all versions)","libarchive (all versions)","libarchive (all versions)","libarchive (all versions)","libarchive (all versions)","libarchive (all versions)","libarchive (all versions)","rhcos (all versions)","rhcos (all versions)","rhcos (all versions)","rhcos (all versions)","rhcos (all versions)","rhcos (all versions)","rhcos (all versions)","discovery/discovery-server-rhel9 (all versions)","discovery/discovery-ui-rhel9 (all versions)","libarchive-main (all versions)","rhui5/cds-kubernetes-rhel9 (all versions)","rhui5/cds-rhel9 (all versions)","rhui5/haproxy-rhel9 (all versions)","rhui5/installer-rhel9 (all versions)","rhui5/rhua-rhel9 (all versions)","rhui5/cds-kubernetes-tp-rhel9 (all versions)","rhui5/installer-tp-rhel9 (all versions)","rhui5/rhua-tp-rhel9 (all versions)","libarchive","libarchive","libarchive","openshift/ose-rhel-coreos-8"],"patched":["openshift_container_platform 4.20","openshift_container_platform 4.22","enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","enterprise_linux_baseos_eus_v_10_0","enterprise_linux_baseos_v_10","enterprise_linux_baseos_e4s_v_9_2","enterprise_linux_baseos_e4s_v_9_4","enterprise_linux_baseos_eus_v_9_6","enterprise_linux_baseos_v_9","discovery 2","hardened_images","update_infrastructure 5"],"published":"2026-06-30","updated":"2026-09-24","sourceUpdated":"2026-09-24T12:17:10.310","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14164","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:30333","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:52674","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:52675","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:54387","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:54760","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:54769","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:56954","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:58558","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:58573","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:58574","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:58981","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:61783","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:62409","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:63041","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:63044","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:63100","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:65839","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:65851","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:67935","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-14164","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493411","label":"secalert@redhat.com"},{"url":"https://github.com/libarchive/libarchive/issues/3069","label":"secalert@redhat.com"},{"url":"https://github.com/libarchive/libarchive/pull/3071","label":"secalert@redhat.com"},{"url":"https://github.com/libarchive/libarchive/issues/3069","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14164.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-14164"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14164"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat"],"epss":0.00488,"epssPercentile":0.4116,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-06-30T12:20:53.891666Z"},"ingestedAt":"2026-08-10T10:39:35.650Z","slug":"CVE-2026-14164","body":"## Overview\n\nA double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:63100** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.20 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:63100)\n- **RHSA-2026:54769** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.22 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:54769)\n- **RHSA-2026:56954** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux BaseOS EUS (v. 10.0) · released 2026-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:56954)\n- **RHSA-2026:52675** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10) · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52675)\n- **RHSA-2026:58574** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2), Red Hat Enterprise Linux BaseOS E4S (v.9.2) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58574)\n- **RHSA-2026:58573** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4), Red Hat Enterprise Linux BaseOS E4S (v.9.4) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58573)\n- **RHSA-2026:58558** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat Enterprise Linux BaseOS EUS (v.9.6) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58558)\n- **RHSA-2026:52674** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9) · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52674)\n- **RHSA-2026:54760** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54760)\n- **RHSA-2026:61783** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61783)\n- **RHSA-2026:30333** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:30333)\n- **RHSA-2026:63041** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.21 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:63041)\n- **RHSA-2026:63044** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:63044)\n- **RHSA-2026:62409** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:62409)\n- **RHSA-2026:65851** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:65851)\n- **RHSA-2026:65839** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:65839)","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":4951,"id":"CVE-2026-14164","ts":1788887218869,"field":"exploit_available","old":"false","new":"true"},{"seq":3834,"id":"CVE-2026-14164","ts":1788886351792,"field":"exploit_available","old":"true","new":"false"},{"seq":2668,"id":"CVE-2026-14164","ts":1788883016458,"field":"exploit_available","old":"false","new":"true"},{"seq":1697,"id":"CVE-2026-14164","ts":1788882420870,"field":"exploit_available","old":"true","new":"false"},{"seq":258,"id":"CVE-2026-14164","ts":1788881643048,"field":"exploit_available","old":"false","new":"true"}]}