Red Hat released Important libarchive security updates for affected RHEL 7 ELS, RHEL 8, and RHEL 9 releases and subscription channels, including OpenShift Container Platform and RHEL-based middleware containers. The updates remediate CVE-2026-4424, a heap out-of-bounds read in RAR processing: a crafted archive can exploit an LZSS dictionary-size validation error after PPMd-to-LZSS transitions to expose heap memory through archive_read_data() before CRC validation. Systems that automatically process untrusted archives may be remotely triggerable without authentication or user interaction.
The releases also fix CVE-2026-5121, an ISO9660 zisofs parsing integer overflow that can allocate an undersized buffer and copy attacker-controlled data beyond its bounds. The resulting heap overflow can potentially enable arbitrary code execution on 32-bit targets, subject to allocator- and platform-specific heap grooming; 64-bit systems do not exhibit the same integer wraparound. Organizations should update libarchive and associated bsdtar, bsdcat, and bsdcpio packages using the applicable Red Hat advisory—for example, RHEL 9 packages 3.5.3-9.el9_7, RHEL 8 packages 3.3.3-7.el8_10, and RHEL 7 ELS packages 3.1.2-14.el7_9.2—or later supported versions.

See affected versions and whether adversaries are exploiting it.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2026:9592 for RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On. It provided libarchive 3.3.3-1.el8_4.2 packages for x86_64 to remediate CVE-2026-4424 and CVE-2026-5121.
Red Hat issued Important advisory RHSA-2026:8866 for RHEL 9.6 lifecycle and update-service offerings. The libarchive 3.5.3-7.el9_6.1 packages remediate CVE-2026-4424 and CVE-2026-5121 on x86_64, aarch64, ppc64le, and s390x.
Red Hat issued Important advisory RHSA-2026:8873 for RHEL 9.4 servicing channels, including EUS, AUS, SAP, four-year-update, and Extended Life Cycle. It supplied libarchive 3.5.3-5.el9_4 and related packages that fix CVE-2026-4424 and CVE-2026-5121.
Red Hat issued Important advisory RHSA-2026:8864 for RHEL 9.2 SAP, AUS, four-year-update, and Extended Life Cycle channels. The advisory supplied fixed libarchive 3.5.3-5.el9_2.2 packages for CVE-2026-4424 and CVE-2026-5121.
Red Hat issued Important advisory RHSA-2026:8867 for RHEL 9.0 Update Services for SAP Solutions. It provided libarchive 3.5.3-2.el9_0.4 for ppc64le, x86_64, aarch64, and s390x systems to address CVE-2026-4424 and CVE-2026-5121.
Red Hat issued Important advisory RHSA-2026:9026 for RHEL 8.8 Extended Life Cycle Long Life, Telecommunications Update Service, and SAP Solutions offerings. The libarchive 3.3.3-5.el8_8.2 update remediates CVE-2026-4424 and CVE-2026-5121.
Red Hat issued Important advisory RHSA-2026:8908 for RHEL 8.6 AMCS, AUS, TUS, SAP Solutions, and long-life channels. It supplied libarchive 3.3.3-6.el8_6.1 packages for x86_64 and ppc64le to fix CVE-2026-4424 and CVE-2026-5121.
Red Hat issued Important advisory RHSA-2026:8510 for RHEL 9, providing libarchive 3.5.3-9.el9_7 and associated utilities. The update remediates CVE-2026-4424 and CVE-2026-5121 for x86_64, s390x, ppc64le, and aarch64 offerings.
Red Hat issued Important advisory RHSA-2026:8534 for RHEL 8 and RHEL 8.10 Extended Life Cycle, supplying libarchive 3.3.3-7.el8_10. The update remediates CVE-2026-4424 and CVE-2026-5121 across x86_64, aarch64, ppc64le, and s390x platforms.
Red Hat issued Important advisory RHSA-2026:8521 for RHEL Server AUS 8.2 on x86_64, providing libarchive 3.3.2-8.el8_2.2. It fixes the RAR out-of-bounds-read flaw CVE-2026-4424 and ISO9660 integer-overflow flaw CVE-2026-5121.
Red Hat issued Important advisory RHSA-2026:8517 for RHEL 7 Extended Lifecycle Support, supplying libarchive 3.1.2-14.el7_9.2. The update remediates CVE-2026-4424 information disclosure and CVE-2026-5121 potential arbitrary code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
13 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.