CVE-2024-26256 is a remote code execution vulnerability in libarchive. The vulnerable code was introduced in libarchive 3.6.0 and fixed upstream in version 3.7.4. Successful exploitation occurs when a vulnerable application or service uses libarchive to process attacker-controlled archive content, potentially allowing arbitrary code execution in the context of the consuming process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a research-grade proof-of-concept set for CVE-2025-5915, a libarchive RAR v4 heap over-read / info-leak in the filter path. It is not a remote exploit framework module; it is a standalone PoC repository combining documentation, archive builders, a macOS disclosure helper, and an iOS on-device demonstration app. Structure: the repo has 42 files. Major directories are writeup/ (long-form English and Italian technical articles), analysis/ (ASan traces, patch diff notes, disassembly excerpts, guard patch, iOS confirmation notes), device-proof/ (captured output from a real iPhone run), and poc/ (actual exploit-building code and iOS harness). Code is primarily Python, Objective-C, C, and Bash. Main exploit capability: generate crafted RAR v4 archives that force libarchive to allocate a tiny LZSS window via a small declared uncompressed size, then request a much larger filter blocklength from attacker-controlled RAR-VM metadata. This causes copy_from_lzss_window() to read beyond the window and copy adjacent heap bytes. The repo demonstrates both crash-oriented ASan reproduction and non-crashing disclosure where leaked heap bytes are emitted into decompressed output. Key exploit files: - poc/build_bigleak.py: modifies a legitimate RAR v4 archive by shrinking UNP_SIZE and recomputing header CRC, producing ~65 KB over-read PoCs from a real sample. - poc/build_encoder.py: full from-scratch RAR v4 encoder that directly controls blocklength and can scale the leak up to the iOS-imposed ceiling (~0x40000 total blocklength, ~256 KB read, ~240 KB disclosed with E8E9 filter). - poc/plant.c: macOS realloc interposer used with DYLD_INSERT_LIBRARIES to place a recognizable secret after the vulnerable window allocation, proving leaked bytes are attacker-observable in output. - poc/RARLeak/: Xcode iOS app that sprays heap with marker LK5915!!, dlopens /usr/lib/libarchive.2.dylib, decompresses embedded malicious RAR data, counts leaked markers, and writes a summary to Documents/rarleak-5915.txt. - poc/RARLeak/build.sh: helper to build/sign/install/launch the iOS app on a connected device. Observed results documented in the repo: ASan logs show heap-buffer-overflow READs in copy_from_lzss_window. Non-ASan transcripts show output far exceeding declared file size and containing planted heap markers. The on-device iOS 18.5 proof reports a 16-byte declared file producing 196608 bytes of output with ~155 KB of nonzero leaked heap and many LK5915!! marker occurrences. Analysis files also show iOS 18.6 contains the backported guard while still reporting libarchive 3.7.4. Overall purpose: demonstrate, validate, and document CVE-2025-5915 as a bounded information disclosure primitive against vulnerable libarchive implementations, especially Apple iOS 18.5’s system libarchive. The repository is a PoC and research artifact, not weaponized malware or a generalized exploitation toolkit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.