Red Hat released security updates for CVE-2026-14164, a Moderate-severity double-free flaw in libarchive's RAR5 decompression logic. The bug stems from a dangling filtered_buf pointer in init_unpack() within archive_read_support_format_rar5.c, allowing a specially crafted RAR5 archive to trigger a second free of the same memory. Red Hat said the issue can crash affected applications and cause denial of service, with impact centered on availability rather than confidentiality or integrity.
The vendor published multiple advisories covering RHEL 9 support streams, including RHSA-2026:58558 for RHEL 9.6, RHSA-2026:58573 for RHEL 9.4 channels, and RHSA-2026:58574 for RHEL 9.2 SAP and lifecycle variants, with updated libarchive packages released across x86_64, aarch64, ppc64le, and s390x. Red Hat's bug tracking also said fixes extend to other products, including RHEL 10 and OpenShift Container Platform 4.22. Tenable published a Nessus detection plugin for exposed RHEL 9 systems and noted that, at publication, no known exploits were available.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat published advisory RHSA-2026:58574 for RHEL 9.2 Update Services for SAP Solutions and related lifecycle variants. The advisory released libarchive 3.5.3-5.el9_2.3 packages to fix CVE-2026-14164 across multiple architectures.
Red Hat published advisory RHSA-2026:58573 for RHEL 9.4 update channels including SAP Solutions, AUS, and Extended Life Cycle variants. The update released libarchive 3.5.3-5.el9_4.2 packages to remediate CVE-2026-14164.
Red Hat published advisory RHSA-2026:58558 for RHEL 9.6 Extended Update Support and related channels, releasing libarchive 3.5.3-7.el9_6.2 to fix CVE-2026-14164 across x86_64, aarch64, ppc64le, and s390x variants.
CVE-2026-14164, a double-free flaw in libarchive's RAR5 decompression logic caused by a dangling filtered_buf pointer in init_unpack(), was published. The issue can be triggered by a crafted RAR5 archive to cause an application crash and denial of service.
Red Hat documented CVE-2026-14164 in Bugzilla entry 2493411, describing the double-free in archive_read_support_format_rar5.c and noting that crafted RAR5 archives could trigger a second free and crash affected applications.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.