Microsoft Security Response Center guidance
CBL-Mariner Releases Release Notes
Vendor-listed releases
- 3.6.1-10
- 3.7.7-6
Vulnerability intelligence
CVE-2026-4424 and is rated High severity with a CVSS score of 7.5. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CBL-Mariner Releases Release Notes
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.