CVE-2026-78322 MEDIUM

CVE-2026-78322: File-roller: file-roller: stack buffer overflow in parse_progress_line for 7z and rar handlers

Vendor Red Hat
Product Red Hat Enterprise Linux 6
Weakness CWE-120
Published August 25, 2026
Last update August 27, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a stack buffer overflow and cause file-roller to terminate, resulting in a denial of service. To exploit this flaw, a victim must open or extract the crafted archive using file-roller.

Key dates

02Disclosure timeline

August 25, 2026 CVE published
August 27, 2026 Record updated