CVE-2024-26256: Libarchive Remote Code Execution Vulnerability
Published Apr 9, 2024
·Updated
libarchive Remote Code Execution Vulnerability
Affected Software
15 affected componentsFixes available
ubuntu/libarchive<3.6.0-1ubuntu1.1
3.6.0-1ubuntu1.1
ubuntu/libarchive<3.6.2-1ubuntu1.1
3.6.2-1ubuntu1.1
ubuntu/libarchive<3.7.2-2ubuntu0.1
3.7.2-2ubuntu0.1
debian/libarchive
3.4.3-2+deb11u13.6.2-1+deb12u13.7.4-1
Microsoft Windows Server 2022, 23H2 Edition
Microsoft Windows 11=23H2
Microsoft Windows 11=23H2
Microsoft Windows 11=22H2
Microsoft Windows 11=22H2
Libarchive libarchive<3.7.4
Fedoraproject Fedora=39
Fedoraproject Fedora=40
Microsoft Windows 11 22h2<10.0.22621.3447
Microsoft Windows 11 23h2<10.0.22631.3447
Microsoft Windows Server 2022 23h2<10.0.25398.830
Remediation
Patch Available
Event History
Apr 9, 2024
CVE Published
via Ubuntu·12:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Jun 28, 2024
Data Sourced
via Launchpad·03:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-26256?
CVE-2024-26256 is classified as a Remote Code Execution vulnerability, which is considered critical in nature.
2
How do I fix CVE-2024-26256?
To mitigate CVE-2024-26256, apply the latest patches provided by Microsoft and Ubuntu based on your system version.
3
What products are affected by CVE-2024-26256?
CVE-2024-26256 affects multiple versions of Microsoft Windows 11, Windows Server 2022, and specific versions of the libarchive package.
4
Is there a workaround for CVE-2024-26256?
Currently, no specific workarounds have been published for CVE-2024-26256, and it is recommended to apply patches as soon as they are available.
5
What is the impact of CVE-2024-26256?
CVE-2024-26256 can lead to unauthorized remote code execution, potentially allowing attackers to take control of the affected system.