Skip to content
Red HatCVE-2026-78322

Red Hat file-roller.: buffer overflow

Medium6.5CVE-2026-78322 · Published Aug 25, 2026 · updated Aug 28, 2026

A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a stack buffer overflow and cause file-roller to terminate, resulting in a denial of service. To exploit this flaw, a victim must open or extract the crafted archive using file-roller.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux: type confusion
Medium5.7Aug 25
Red Hat Enterprise Linux: stack buffer overflow
High7.6Aug 25
Red Hat file-xwd plugin: out-of-bounds read
Medium4.4Aug 25
An algorithmic complexity flaw exists in libsoup's HTTP Range header processing
Medium5.3Aug 25
Red Hat Emacs TRAMP. A local attacker: code execution
High7.8Aug 25
Red Hat Ansible Automation Platform 2: server-side request forgery
Medium6.4Aug 25

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.