Buffer Overflow Vulnerability in File Roller by GNOME
CVE-2026-78322

6.5MEDIUM

What is CVE-2026-78322?

A vulnerability exists in File Roller, a popular archive management tool, where it improperly handles the extraction of malicious 7z or RAR archives containing excessively long file path entries. The flaw arises as File Roller attempts to parse the progress line of these archives, causing it to copy the path into a fixed-size stack buffer without proper bounds checking. This can lead to a stack buffer overflow, which may result in the application crashing and potentially allow a denial of service if exploited. Users must exercise caution when opening or extracting archives from untrusted sources.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Yukihiro Nakamura for reporting this issue.
.