CVE-2024-26256

Libarchive Remote Code Execution Vulnerability
Configurations

Configuration 1 (hide)

cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*

History

08 Jan 2025, 16:03

Type Values Removed Values Added
First Time Microsoft
Microsoft windows 11 23h2
Microsoft windows Server 2022 23h2
Fedoraproject fedora
Fedoraproject
Microsoft windows 11 22h2
Libarchive libarchive
Libarchive
CPE cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*
CWE CWE-787
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26256 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26256 - Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2024/06/04/2 - () http://www.openwall.com/lists/oss-security/2024/06/04/2 - Mailing List
References () http://www.openwall.com/lists/oss-security/2024/06/05/1 - () http://www.openwall.com/lists/oss-security/2024/06/05/1 - Mailing List
References () https://github.com/LeSuisse/nixpkgs/commit/81b82a2934521dffef76f7ca305d8d4e22fe7262 - () https://github.com/LeSuisse/nixpkgs/commit/81b82a2934521dffef76f7ca305d8d4e22fe7262 - Patch
References () https://github.com/libarchive/libarchive/commit/eb7939b24a681a04648a59cdebd386b1e9dc9237.patch - () https://github.com/libarchive/libarchive/commit/eb7939b24a681a04648a59cdebd386b1e9dc9237.patch - Patch
References () https://github.com/libarchive/libarchive/releases/tag/v3.7.4 - () https://github.com/libarchive/libarchive/releases/tag/v3.7.4 - Release Notes
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EWANFZ6NEMXFCALXWI2AFKYBOLONAVFC/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EWANFZ6NEMXFCALXWI2AFKYBOLONAVFC/ - Mailing List
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TWAMR5TY47UKVYMWQXB34CWSBNTRYMBV/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TWAMR5TY47UKVYMWQXB34CWSBNTRYMBV/ - Mailing List
References () https://www.openwall.com/lists/oss-security/2024/06/04/2 - () https://www.openwall.com/lists/oss-security/2024/06/04/2 - Mailing List

21 Nov 2024, 09:02

Type Values Removed Values Added
Summary (en) libarchive Remote Code Execution Vulnerability (en) Libarchive Remote Code Execution Vulnerability
References
  • () http://www.openwall.com/lists/oss-security/2024/06/04/2 -
  • () http://www.openwall.com/lists/oss-security/2024/06/05/1 -
  • () https://github.com/LeSuisse/nixpkgs/commit/81b82a2934521dffef76f7ca305d8d4e22fe7262 -
  • () https://github.com/libarchive/libarchive/commit/eb7939b24a681a04648a59cdebd386b1e9dc9237.patch -
  • () https://github.com/libarchive/libarchive/releases/tag/v3.7.4 -
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EWANFZ6NEMXFCALXWI2AFKYBOLONAVFC/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TWAMR5TY47UKVYMWQXB34CWSBNTRYMBV/ -
  • () https://www.openwall.com/lists/oss-security/2024/06/04/2 -
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26256 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26256 -

09 Oct 2024, 02:15

Type Values Removed Values Added
References
  • {'url': 'http://www.openwall.com/lists/oss-security/2024/06/04/2', 'source': 'secure@microsoft.com'}
  • {'url': 'http://www.openwall.com/lists/oss-security/2024/06/05/1', 'source': 'secure@microsoft.com'}
  • {'url': 'https://github.com/LeSuisse/nixpkgs/commit/81b82a2934521dffef76f7ca305d8d4e22fe7262', 'source': 'secure@microsoft.com'}
  • {'url': 'https://github.com/libarchive/libarchive/commit/eb7939b24a681a04648a59cdebd386b1e9dc9237.patch', 'source': 'secure@microsoft.com'}
  • {'url': 'https://github.com/libarchive/libarchive/releases/tag/v3.7.4', 'source': 'secure@microsoft.com'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EWANFZ6NEMXFCALXWI2AFKYBOLONAVFC/', 'source': 'secure@microsoft.com'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TWAMR5TY47UKVYMWQXB34CWSBNTRYMBV/', 'source': 'secure@microsoft.com'}
  • {'url': 'https://www.openwall.com/lists/oss-security/2024/06/04/2', 'source': 'secure@microsoft.com'}

12 Jun 2024, 02:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TWAMR5TY47UKVYMWQXB34CWSBNTRYMBV/ -

10 Jun 2024, 18:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/06/04/2 -
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EWANFZ6NEMXFCALXWI2AFKYBOLONAVFC/ -

10 Jun 2024, 17:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/06/05/1 -

08 Jun 2024, 13:15

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de ejecución remota de código de libarchive
References
  • () https://github.com/LeSuisse/nixpkgs/commit/81b82a2934521dffef76f7ca305d8d4e22fe7262 -
  • () https://github.com/libarchive/libarchive/commit/eb7939b24a681a04648a59cdebd386b1e9dc9237.patch -
  • () https://github.com/libarchive/libarchive/releases/tag/v3.7.4 -
  • () https://www.openwall.com/lists/oss-security/2024/06/04/2 -

09 Apr 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-09 17:15

Updated : 2025-01-08 16:03


NVD link : CVE-2024-26256

Mitre link : CVE-2024-26256

CVE.ORG link : CVE-2024-26256


JSON object : View

Products Affected

fedoraproject

  • fedora

microsoft

  • windows_server_2022_23h2
  • windows_11_23h2
  • windows_11_22h2

libarchive

  • libarchive
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write