CVE-2026-88340
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 03:48
Description
An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free in yr_rules_destroy() or wild pointer access in yr_object_create(). An attacker can provide a specially crafted .yrc file that causes memory corruption and application crash.
Aliases and classifications
Minimised technical details
No raw data- cisa kev
- False
- cvss score
- 7.6
- cvss vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
- cvss severity
- HIGH
Public references
- https://github.com/VirusTotal/yara/pull/2244/changes/8d7bef643ee5fa2381e235bcedf80170a6b00d3b
https://github.com/VirusTotal/yara/pull/2244/changes/8d7bef643ee5fa2381e235bcedf80170a6b00d3b - https://github.com/VirusTotal/yara/issues/2239
https://github.com/VirusTotal/yara/issues/2239 - https://github.com/VirusTotal/yara/pull/2244
https://github.com/VirusTotal/yara/pull/2244
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.