CVE-2026-15028

⚪ Do wiadomości

Przepełnienie sterty w libarchive umożliwia zdalne wykonanie kodu lub powoduje awarię systemu.

CVSS
3.9
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.

buffer-overflow dos rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS3.9
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-07-10 10:16:23 UTC
Ostatnia modyfikacja (NVD)2026-08-21 13:16:52 UTC
Referencje