Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-80400.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-80400
Upstream
  • CVE-2026-4426
Published
2026-03-19T15:16:28Z
Modified
2026-09-05T05:27:51Z
Summary
CVE-2026-4426 affecting package libarchive for versions less than 3.7.7-6
Details

A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (pz_log2_bs) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.

References

Affected packages

Azure Linux:3 / libarchive

Package

Name
libarchive
Purl
pkg:rpm/azure-linux/libarchive

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.7.7-6

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-80400.json"