HIGH
VirusTotal
CVE published 2026-09-22
CVE-2026-88340
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-22T20:17:10.250Z and has not been modified since then. The vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files due to insufficient validation of external-variable pointers. This may lead to invalid free in yr_rules_destroy() or wild pointer access in yr_object_creat [truncated]