How Unrar Handles Malformed and Malicious Archives

This article examines how the unrar utility responds to malformed and malicious RAR archives, covering its standard error-handling routines, behavior during path traversal attempts, and risks related to memory corruption. It details how the utility validates archive headers, prevents directory escapes, and handles crafted compression payloads designed to trigger unexpected execution states.

Structural Validation and Error Detection

When unrar processes an archive, it sequentially parses discrete data blocks (such as the main archive header, file headers, and service records). If any block contains invalid flags, unexpected data lengths, or inconsistent metadata, the utility halts execution or skips the affected stream.

Common behaviors during non-malicious structural failures include:

  • CRC Mismatches: If an extracted file does not match the internal cyclic redundancy check (CRC32 or BLAKE2sp in RAR5), unrar flags a checksum error. By default, it deletes the partially extracted file unless the keep-broken-files switch (-kb) is specified.
  • Corrupt Headers: If a header size field is smaller than the minimum structural requirement or points past the end of the file (EOF), unrar terminates parsing immediately and returns an exit code indicating a fatal archive error.
  • Truncated Archives: If a file terminates prematurely during decompression, the unpacker reports an unexpected end-of-archive and exits without completing the remaining queue.

Path Traversal and Directory Escapes

A primary vector in malicious archives is directory traversal, where archive entries include filenames containing relative path sequences (e.g., ../../etc/passwd) or absolute paths (e.g., /usr/bin/target).

In modern, patched versions of unrar:

  • Path Sanitization: The utility strips absolute path indicators (such as leading / on Unix-like systems or drive letters like C:\ on Windows) and resolves .. components before writing files to the disk.
  • Root Confinement: Files are restricted to the destination directory specified on the command line. Any attempts to escape this root folder are blocked, and unrar normalizes the path to extract the file safely within the designated target folder.

Historical vulnerabilities, such as CVE-2022-30333, demonstrated that insufficient validation of symbolic links or specific directory components in older Unix ports allowed arbitrary file writes outside target boundaries. Current releases strictly sanitize link destinations and directory names to prevent this behavior.

Malicious archives can contain symbolic links designed to point to sensitive system locations. If an archive extracts a symlink pointing to a system file and subsequently extracts a regular file targeting that same path, it could overwrite unauthorized data.

To counter this:

  • unrar prevents absolute symlink targets by default or rejects symlinks that resolve outside the extraction root directory.
  • On platforms where symlinks require elevated permissions (such as standard user accounts on modern Windows), unrar skips symlink creation entirely or issues a warning without elevating operations.

Decompression Engine and Memory Safety

The core decompression routines of unrar are implemented in C++, making the tool historically sensitive to memory-safety bugs when parsing adversarial inputs. Attackers craft malformed compression dictionaries, Huffman tables, or run-length encoding (RLE) sequences to trigger:

  • Out-of-Bounds Reads/Writes: Malformed Huffman trees can cause the unpacker to read from or write to memory outside the allocated decompression buffer.
  • Integer Overflows: Manipulated packed-size and unpacked-size fields can cause the application to allocate an insufficient buffer, leading to subsequent heap-based buffer overflows.

Modern builds of unrar incorporate strict boundary checks across the RAR decompression routines (covering RAR 1.5 through RAR 5.0 formats). When invalid decompression parameters are detected, the decompression state machine aborts, prints a read or unpack error, and cleanly unwinds execution rather than continuing to process corrupted data.

Exit Codes and Automation Impact

When deployed in automated environments (such as mail gateways, antivirus scanners, or ingestion pipelines), unrar signals anomalies using specific process exit codes:

  • Code 0: Successful extraction.
  • Code 1: Non-fatal warning (e.g., checksum error while using -kb).
  • Code 2: A fatal error occurred during extraction.
  • Code 3: Invalid checksum detected; extraction output rejected.
  • Code 4: Attempt to modify a locked archive or write error.
  • Code 9: File creation or permission failure.

Automated systems processing untrusted archives rely on these non-zero exit codes to quarantine files, reject malformed payloads, and avoid passing broken or partially unpacked artifacts downstream.