CVE-2019-18408: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 4% chance of exploitation in the next 30 days.

archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 8.0 only
  • Libarchive Libarchive: before 3.4.0 (fixed in 3.4.0)

Published 2019-10-24. Last modified 2026-06-17.