CVE-2026-24857 is a critical heap-buffer-overflow vulnerability affecting simsong bulk_extractor versions 1.4 and later. A specially crafted RAR file embedded within a disk image can trigger an out-of-bounds write during RAR PPM LZ decoding, leading to application crashes and potential memory corruption. With a CVSS score of 9.8, this vulnerability poses a significant risk of Remote Code Execution (RCE) due to its network-based attack vector, low attack complexity, and lack of user interaction. As of now, there are no known patches, active exploits, or publicly available exploit code, and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.4CPE matchmatch criteria | cpe:2.3:a:simsong:bulk_extractor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.