Vulnerability Intelligence Report
Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing
CVE-2026-5121
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:1.07%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-190 ↗Integer Overflow or Wraparound
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:3.1.2-14.el7_9.2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8 | 0:3.3.3-7.el8_10 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.2 Advanced Update Support | 0:3.3.2-8.el8_2.2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:3.3.3-1.el8_4.2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 0:3.3.3-1.el8_4.2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:3.3.3-6.el8_6.1 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.6 Telecommunications Update Service | 0:3.3.3-6.el8_6.1 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | 0:3.3.3-6.el8_6.1 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:3.3.3-5.el8_8.2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:3.3.3-5.el8_8.2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9 | 0:3.5.3-9.el9_7 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9 | 0:3.5.3-9.el9_7 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | 0:3.5.3-2.el9_0.4 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:3.5.3-5.el9_2.2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | 0:3.5.3-5.el9_4 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:3.5.3-7.el9_6.1 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 412.86.202604281506-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 413.92.202605271328-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 414.92.202605060243-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 415.92.202605060220-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 416.94.202604211449-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 417.94.202605112123-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 418.94.202604240015-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 4.19.9.6.202605201155-0 < * (unaffected) |
| Red Hat | RHEL-8 based Middleware Containers | 7.13.5-4.1777325677 < * (unaffected) |
| Red Hat | RHEL-8 based Middleware Containers | 7.13.5-4.1777325711 < * (unaffected) |
| Red Hat | RHEL-8 based Middleware Containers | 7.13.5-4.1777325710 < * (unaffected) |
| Red Hat | RHEL-8 based Middleware Containers | 7.13.5-3.1777325680 < * (unaffected) |
| Red Hat | RHEL-8 based Middleware Containers | 7.13.5-4.1777325709 < * (unaffected) |
| Red Hat | RHEL-8 based Middleware Containers | 7.13.5-4.1777325680 < * (unaffected) |
| Red Hat | RHEL-8 based Middleware Containers | 7.13.5-4.1777325708 < * (unaffected) |
| Red Hat | Red Hat AI Inference Server 3.2 | 1779223654 < * (unaffected) |
| Red Hat | Red Hat AI Inference Server 3.2 | 1779223651 < * (unaffected) |
| Red Hat | Red Hat AI Inference Server 3.2 | 1780681984 < * (unaffected) |
| Red Hat | Red Hat AI Inference Server 3.3 | 1778244559 < * (unaffected) |
| Red Hat | Red Hat AI Inference Server 3.3 | 1778244531 < * (unaffected) |
| Red Hat | Red Hat AI Inference Server 3.3 | 1778274666 < * (unaffected) |
| Red Hat | Red Hat AI Inference Server 3.3 | 1778244546 < * (unaffected) |
| Red Hat | Red Hat Discovery 2 | 1778156756 < * (unaffected) |
| Red Hat | Red Hat Hardened Images | 3.8.7-1.hum1 < * (unaffected) |
| Red Hat | Red Hat Insights proxy 1.5 | 1776868961 < * (unaffected) |
| Red Hat | Red Hat Update Infrastructure 5 | 1776868774 < * (unaffected) |
| Red Hat | Red Hat Update Infrastructure 5 | 1776868744 < * (unaffected) |
| Red Hat | Red Hat Update Infrastructure 5 | 1776868772 < * (unaffected) |
| Red Hat | Red Hat Update Infrastructure 5 | 1776868842 < * (unaffected) |
| Red Hat | Red Hat Update Infrastructure 5 | 1777459441 < * (unaffected) |
| Red Hat | Red Hat Update Infrastructure 5 | 1777454300 < * (unaffected) |
| Red Hat | Red Hat Update Infrastructure 5 | 1777459504 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 10 | all |
| Red Hat | Red Hat Enterprise Linux 6 | all |
| Red Hat | Red Hat OpenShift Container Platform 4 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.073%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2026-03-30T07:39:27 |
| Published | 2026-03-30T07:47:28 |
| Patch Date | 2026-03-30 |
| Last Updated | 2026-09-01T08:38:36 |
Community Chatter & Buzz