9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
Basic Information
ID
CVE-2026-5121
Source
redhat
Published
Mar 30, 2026 at 07:47
Modified
Apr 9, 2026 at 16:33
Affected Product
Vendor
Red Hat
Product
Red Hat Enterprise Linux 10