CVE-2026-5745
Alma Linux vulnerability analysis and mitigation

Overview

CVE-2026-5745 is a NULL pointer dereference vulnerability in libarchive's ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string — such as a bare "d" or "default" tag without subsequent fields — the function fails to validate the pointer before advancing it, leading to a crash. Affected software includes libarchive (all versions tracked under the CPE) and downstream Red Hat products including Red Hat Enterprise Linux 6.0–10.0, OpenShift Container Platform 4.0, and Red Hat Hardened Images. The vulnerability was disclosed on April 7, 2026, and carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Github Advisory).

Technical details

The root cause is classified as CWE-476 (NULL Pointer Dereference). The archive_acl_from_text_nl() function in libarchive does not perform adequate validation when it encounters a malformed ACL entry — specifically, an ACL tag such as "d" or "default" that is not followed by the expected subsequent fields. The function advances an internal pointer without confirming it points to valid data, resulting in a NULL dereference when the pointer is later used. Exploitation requires an attacker to supply a maliciously crafted archive file to a user or process that opens it with a libarchive-based application (e.g., bsdtar), making user interaction a prerequisite (Red Hat Bugzilla, Github Advisory).

Impact

Successful exploitation causes the affected application (such as bsdtar, bsdcpio, or any software using the libarchive API) to crash, resulting in a Denial of Service (DoS). There is no impact on confidentiality or integrity — only availability is affected. The scope is limited to the vulnerable component itself, with no privilege escalation or lateral movement potential identified (Red Hat CVE, Github Advisory).

Exploitability

There is no known public proof-of-concept exploit code or evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (0th percentile), indicating a very low probability of exploitation in the near term (Github Advisory, Red Hat CVE).

Exploitation steps

  1. Craft a malicious archive: Create an archive file (e.g., tar format) that contains a malformed ACL string in its metadata — specifically, an ACL entry with only a bare "d" or "default" tag and no subsequent fields.
  2. Deliver the archive: Distribute the crafted archive to a target user or system where a libarchive-based application (such as bsdtar) is installed, via email attachment, file share, or web download.
  3. Trigger processing: Induce the target user to open or extract the archive using bsdtar or another libarchive-consuming application (user interaction is required).
  4. Achieve DoS: When archive_acl_from_text_nl() processes the malformed ACL string, it dereferences a NULL pointer, causing the application to crash and resulting in a Denial of Service (Red Hat Bugzilla, Github Advisory).

Indicators of compromise

  • Logs: Application crash logs or core dumps from bsdtar, bsdcpio, or other libarchive-based tools, particularly referencing a segmentation fault or NULL pointer dereference in archive_acl_from_text_nl().
  • File System: Presence of unexpected or suspicious archive files (e.g., .tar, .tar.gz) with unusual or minimal ACL metadata in directories accessible to users.
  • Process: Abnormal termination (exit code indicating signal, e.g., SIGSEGV) of bsdtar or related processes shortly after opening an archive file.

Mitigation and workarounds

Red Hat has released a patched version of libarchive (3.8.7-1.hum1) for Red Hat Hardened Images via security advisory RHSA-2026:8944, issued April 20, 2026. Users of Red Hat Enterprise Linux and OpenShift Container Platform should apply available errata updates as they become available through the Red Hat Customer Portal. As a workaround, avoid opening untrusted archive files with libarchive-based tools until patches are applied (Red Hat Errata, Red Hat CVE).

Community reactions

The vulnerability was reported and tracked through Red Hat's OSIDB system and published to the GitHub Advisory Database on April 7, 2026. The Yocto Project security mailing list also discussed the CVE in the context of OE-Core CVE metrics. No notable researcher commentary or significant media coverage has been identified beyond standard vulnerability database entries (Github Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

libarchive

Affected

sid

libarchive: 3.8.8-1

Fixed

trixie

libarchive

Affected

Ubuntu

Fixed

bionic (esm-infra)

libarchive

Not Affected

devel

libarchive

Not Affected

focal (esm-infra)

libarchive: 3.4.0-2ubuntu1.5+esm3

Fixed

jammy

libarchive: 3.6.0-1ubuntu1.8

Fixed

noble

libarchive: 3.7.2-2ubuntu0.8

Fixed

resolute

libarchive: 3.8.5-1ubuntu2.2

Fixed

trusty (esm-infra-legacy)

libarchive

Not Affected

xenial (esm-infra-legacy)

libarchive

Not Affected

RHEL / CentOS

Affected

OpenShift

openshift/ose-rhel-coreos-8

Affected

RHEL 8

libarchive.src

Affected

RHEL 9

libarchive.src

Affected

RHEL 10

libarchive.src

Affected

SourceThis report was generated using AI

Related Alma Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18922CRITICAL9.8
  • Rocky Linux logoRocky Linux
  • 389-ds-base-snmp-debuginfo
NoYesSep 07, 2026
CVE-2026-44950CRITICAL9.5
  • Rocky Linux logoRocky Linux
  • libXfont-debuginfo
NoYesSep 10, 2026
CVE-2026-59679CRITICAL9.2
  • Rocky Linux logoRocky Linux
  • libXfont2-doc
NoYesSep 10, 2026
CVE-2026-18453HIGH7.5
  • Rocky Linux logoRocky Linux
  • 389-ds:1.4::389-ds-base
NoYesSep 07, 2026
CVE-2026-18355HIGH7.5
  • Rocky Linux logoRocky Linux
  • 389-ds-base-snmp
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management