CVE-2026-88340
CVE-2026-88340 is a high-severity vulnerability with a CVSS 3.x base score of 7.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-763.
Key facts
- Severity: High (CVSS 3.x base score 7.6)
- EPSS exploit prediction: 0% (15th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-763
- Published:
- Last modified:
Description
An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free in yr_rules_destroy() or wild pointer access in yr_object_create(). An attacker can provide a specially crafted .yrc file that causes memory corruption and application crash.
Frequently asked questions
- What is CVE-2026-88340?
- An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free in yr_rules_destroy() or wild pointer access in yr_object_create(). An attacker can provide a specially crafted .yrc file that causes memory corruption and application crash.
- How severe is CVE-2026-88340?
- CVE-2026-88340 has a CVSS 3.x base score of 7.6, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is low, integrity low, and availability high.
- Is CVE-2026-88340 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (15th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-88340?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-88340 published?
- CVE-2026-88340 was published on 2026-09-22 and last updated on 2026-09-25.
References
- https://github.com/VirusTotal/yara/issues/2239
- https://github.com/VirusTotal/yara/pull/2244
- https://github.com/VirusTotal/yara/pull/2244/changes/8d7bef643ee5fa2381e235bcedf80170a6b00d3b
Other CWE-763 vulnerabilities
- CVE-2025-14233 — Critical (CVSS 9.8): Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may…
- CVE-2024-44852 — Critical (CVSS 9.8): Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation…
- CVE-2021-42377 — Critical (CVSS 9.8): An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution…
- CVE-2021-30473 — Critical (CVSS 9.8): aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
- CVE-2021-24028 — Critical (CVSS 9.8): An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code…
- CVE-2020-0103 — Critical (CVSS 9.8): In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This…