CVE-2026-24857
CRITICALSimsong Bulk Extractor - Out-of-Bounds Write
Title source: ruleDescription
`bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar code has a heap‑buffer‑overflow in the RAR PPM LZ decoding path. A crafted RAR inside a disk image causes an out‑of‑bounds write in `Unpack::CopyString`, leading to a crash under ASAN (and likely a crash or memory corruption in production builds). There's potential for using this for RCE. As of time of publication, no known patches are available.
Scores
CVSS v3
9.8
EPSS
0.0008
EPSS Percentile
24.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-787
CWE-122
Status
published
Affected Products (1)
simsong/bulk_extractor
Timeline
Published
Jan 28, 2026
Tracked Since
Feb 18, 2026