{"id":"UBUNTU-CVE-2026-78322","details":"A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a stack buffer overflow and cause file-roller to terminate, resulting in a denial of service. To exploit this flaw, a victim must open or extract the crafted archive using file-roller.","modified":"2026-09-11T20:53:36.557210168Z","published":"2026-08-25T08:18:00Z","upstream":["CVE-2026-78322"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-78322"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-78322"}],"affected":[{"package":{"name":"file-roller","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/file-roller?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.16.4-1ubuntu3","3.16.5-0ubuntu1","3.16.5-0ubuntu1.1","3.16.5-0ubuntu1.2","3.16.5-0ubuntu1.3","3.16.5-0ubuntu1.4","3.16.5-0ubuntu1.5"],"ecosystem_specific":{"priority_reason":"Limited to a crash in a GUI tool because of compiler hardening","binaries":[{"binary_name":"file-roller","binary_version":"3.16.5-0ubuntu1.5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-78322.json"}},{"package":{"name":"file-roller","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/file-roller?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.26.1-0ubuntu1","3.26.2-0ubuntu1","3.26.2-3ubuntu1","3.28.0-1ubuntu1","3.28.0-1ubuntu1.1","3.28.0-1ubuntu1.2","3.28.0-1ubuntu1.3"],"ecosystem_specific":{"priority_reason":"Limited to a crash in a GUI tool because of compiler hardening","binaries":[{"binary_version":"3.28.0-1ubuntu1.3","binary_name":"file-roller"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-78322.json"}},{"package":{"name":"file-roller","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/file-roller?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.32.2-1","3.32.3-1","3.35.90-1","3.35.91-1","3.35.92-1","3.36.0-1","3.36.1-1","3.36.1-1ubuntu0.1","3.36.2-0ubuntu1","3.36.3-0ubuntu1","3.36.3-0ubuntu1.1"],"ecosystem_specific":{"priority_reason":"Limited to a crash in a GUI tool because of compiler hardening","binaries":[{"binary_name":"file-roller","binary_version":"3.36.3-0ubuntu1.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-78322.json"}},{"package":{"name":"file-roller","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/file-roller?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.40.0-2","3.40.0-3","3.40.0-4","3.41.90-1","3.42.0-1"],"ecosystem_specific":{"binaries":[{"binary_name":"file-roller","binary_version":"3.42.0-1"}],"priority_reason":"Limited to a crash in a GUI tool because of compiler hardening"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-78322.json"}},{"package":{"name":"file-roller","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/file-roller?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["43.0-1","43.1-1","43.1-1build1","43.1-1build2","44.1-1","44.3-0ubuntu1","44.3-0ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_version":"44.3-0ubuntu2","binary_name":"file-roller"}],"priority_reason":"Limited to a crash in a GUI tool because of compiler hardening"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-78322.json"}},{"package":{"name":"file-roller","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/file-roller?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["44.5-1","44.6-1","44.6-2","44.6-3"],"ecosystem_specific":{"binaries":[{"binary_name":"file-roller","binary_version":"44.6-3"}],"priority_reason":"Limited to a crash in a GUI tool because of compiler hardening"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-78322.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"low"}]}