A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a stack buffer overflow and cause file-roller to terminate, resulting in a denial of service. To exploit this flaw, a victim must open or extract the crafted archive using file-roller.
{
"cna_assigner": "redhat",
"cwe_ids": [
"CWE-120"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78322.json"
}"2026-08-28T08:05:19Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78322.json"
[
{
"deprecated": false,
"target": {
"file": "src/fr-command-7z.c"
},
"signature_type": "Line",
"source": "https://gitlab.gnome.org/gnome/file-roller@ffb76dc866342cef6a4914873faaa880d14d5aa4",
"digest": {
"line_hashes": [
"71739100515079171671998399096634081849",
"44225993571777629518978982114950248584",
"116814765018101274206339891031341346239",
"66377892175672793800759435118149697766",
"218835721609726306582542627341966370745",
"159874825550173311683638355025478839445"
],
"threshold": 0.9
},
"signature_version": "v1",
"id": "CVE-2026-78322-12c1fc5c"
},
{
"deprecated": false,
"target": {
"function": "parse_progress_line",
"file": "src/fr-command-7z.c"
},
"signature_version": "v1",
"source": "https://gitlab.gnome.org/gnome/file-roller@ffb76dc866342cef6a4914873faaa880d14d5aa4",
"digest": {
"length": 440.0,
"function_hash": "174967199003939698779035571221065610481"
},
"signature_type": "Function",
"id": "CVE-2026-78322-3ff60830"
},
{
"deprecated": false,
"target": {
"function": "parse_progress_line",
"file": "src/fr-command-rar.c"
},
"signature_type": "Function",
"source": "https://gitlab.gnome.org/gnome/file-roller@ffb76dc866342cef6a4914873faaa880d14d5aa4",
"digest": {
"length": 687.0,
"function_hash": "179279891939609539761108533567531690102"
},
"signature_version": "v1",
"id": "CVE-2026-78322-99b78b7a"
},
{
"deprecated": false,
"target": {
"file": "src/fr-command-rar.c"
},
"signature_type": "Line",
"source": "https://gitlab.gnome.org/gnome/file-roller@ffb76dc866342cef6a4914873faaa880d14d5aa4",
"digest": {
"line_hashes": [
"92260839491535988139078718339886733309",
"182539522940278318377020722814724026958",
"64700519157211002289537761807881588040",
"93482715441768267065952137702065150808",
"233239623374405993071744805293670784223",
"56051078724194283299607863466862266744",
"59130114841488213729528654758529918807",
"93086555017822165329417402925558998156"
],
"threshold": 0.9
},
"signature_version": "v1",
"id": "CVE-2026-78322-ef3b564d"
}
]