CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-5745

mediumcovered by 2 sourcesfirst seen 2026-07-21
It was discovered that libarchive did not properly manage memory when unpacking certain RAR5 archives, leading to a double free. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-14164) It was discovered that libarchive did not properly validate certain tar archives, leading to a buffer overflow. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15028) It was discovered that libarchive did not properly validate certain malformed ACL entries. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-5745)

CSIRTS triage

What
Multiple vulnerabilities exist that can lead to denial of service or arbitrary code execution.
Who is affected
Users of libarchive on Ubuntu 26.04 LTS.
Urgency
Remediation is important due to the potential for denial of service and code execution.
Action
Update libarchive to the latest version to address these vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-5745

Get an email if CVE-2026-5745 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-5745

CVE.org record

Embed the live status

CVE-2026-5745 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-5745 status](https://www.csirts.com/badge/CVE-2026-5745)](https://www.csirts.com/cve/CVE-2026-5745)