Back to overview

CVE-2026-5121

CRITICAL
9.8
CVSS 3.1
Description
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.

Metadata

CVE ID
CVE-2026-5121
State
PUBLISHED
Assigner
redhat
Reserved
2026-03-30 07:39 UTC
Published
2026-03-30 07:47 UTC
Last updated
2026-07-14 12:45 UTC
Primary CWE
CWE-190
Integer Overflow or Wraparound
Vendor / Product
Red Hat / Red Hat Enterprise Linux 7 Extended Lifecycle Support
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (50)
VendorProductPlatformVersions
Red Hat Red Hat AI Inference Server 3.2 1779223654 < *
Red Hat Red Hat AI Inference Server 3.2 1779223651 < *
Red Hat Red Hat AI Inference Server 3.2 1780681984 < *
Red Hat Red Hat AI Inference Server 3.3 1778244559 < *
Red Hat Red Hat AI Inference Server 3.3 1778244531 < *
Red Hat Red Hat AI Inference Server 3.3 1778274666 < *
Red Hat Red Hat AI Inference Server 3.3 1778244546 < *
Red Hat Red Hat Discovery 2 1778156756 < *
Red Hat Red Hat Enterprise Linux 10
Red Hat Red Hat Enterprise Linux 6
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:3.1.2-14.el7_9.2 < *
Red Hat Red Hat Enterprise Linux 8 0:3.3.3-7.el8_10 < *
Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support 0:3.3.2-8.el8_2.2 < *
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:3.3.3-1.el8_4.2 < *
Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 0:3.3.3-1.el8_4.2 < *
Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 0:3.3.3-6.el8_6.1 < *
Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service 0:3.3.3-6.el8_6.1 < *
Red Hat Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions 0:3.3.3-6.el8_6.1 < *
Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service 0:3.3.3-5.el8_8.2 < *
Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions 0:3.3.3-5.el8_8.2 < *
Red Hat Red Hat Enterprise Linux 9 0:3.5.3-9.el9_7 < *
Red Hat Red Hat Enterprise Linux 9 0:3.5.3-9.el9_7 < *
Red Hat Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions 0:3.5.3-2.el9_0.4 < *
Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions 0:3.5.3-5.el9_2.2 < *
Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support 0:3.5.3-5.el9_4 < *
Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support 0:3.5.3-7.el9_6.1 < *
Red Hat Red Hat Hardened Images 3.8.7-1.hum1 < *
Red Hat Red Hat Insights proxy 1.5 1776868961 < *
Red Hat Red Hat OpenShift Container Platform 4.12 412.86.202604281506-0 < *
Red Hat Red Hat OpenShift Container Platform 4.13 413.92.202605271328-0 < *
Red Hat Red Hat OpenShift Container Platform 4.14 414.92.202605060243-0 < *
Red Hat Red Hat OpenShift Container Platform 4.15 415.92.202605060220-0 < *
Red Hat Red Hat OpenShift Container Platform 4.16 416.94.202604211449-0 < *
Red Hat Red Hat OpenShift Container Platform 4.17 417.94.202605112123-0 < *
Red Hat Red Hat OpenShift Container Platform 4.18 418.94.202604240015-0 < *
Red Hat Red Hat OpenShift Container Platform 4.19 4.19.9.6.202605201155-0 < *
Red Hat Red Hat Update Infrastructure 5 1776868774 < *
Red Hat Red Hat Update Infrastructure 5 1776868744 < *
Red Hat Red Hat Update Infrastructure 5 1776868772 < *
Red Hat Red Hat Update Infrastructure 5 1776868842 < *
Red Hat Red Hat Update Infrastructure 5 1777459441 < *
Red Hat Red Hat Update Infrastructure 5 1777454300 < *
Red Hat Red Hat Update Infrastructure 5 1777459504 < *
Red Hat RHEL-8 based Middleware Containers 7.13.5-4.1777325677 < *
Red Hat RHEL-8 based Middleware Containers 7.13.5-4.1777325711 < *
Red Hat RHEL-8 based Middleware Containers 7.13.5-4.1777325710 < *
Red Hat RHEL-8 based Middleware Containers 7.13.5-3.1777325680 < *
Red Hat RHEL-8 based Middleware Containers 7.13.5-4.1777325709 < *
Red Hat RHEL-8 based Middleware Containers 7.13.5-4.1777325680 < *
Red Hat RHEL-8 based Middleware Containers 7.13.5-4.1777325708 < *
Weakness (CWE)
CWESourceDescription
CWE-190 cna Integer Overflow or Wraparound
CWE-190 adp CWE-190 Integer Overflow or Wraparound
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References (36)
Back to overview