|
|
Log in / Subscribe / Register

Debian alert DLA-4762-1 (libarchive)

From:  Abhijith PA <abhijith@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4762-1] libarchive security update
Date:  Mon, 31 Aug 2026 12:55:16 +0530
Message-ID:  <apUsXEQS5FNyTdlI@debian.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4762-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Abhijith PA August 31, 2026 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libarchive Version : 3.4.3-2+deb11u5 3.6.2-1+deb12u5 CVE ID : CVE-2026-14164 CVE-2026-15028 CVE-2026-16517 Several vulnerabilities were discovered in libarchive, a multi-format archive and compression library CVE-2026-14164 A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service. CVE-2026-15028 A remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system. CVE-2026-16517 A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption. For Debian 11 bullseye, these problems have been fixed in version 3.4.3-2+deb11u5. For Debian 12 bookworm, these problems have been fixed in version 3.6.2-1+deb12u5. We recommend that you upgrade your libarchive packages. For the detailed security status of libarchive please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libarchive Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqVLFwACgkQhj1N8u2c KO9tEA//QQsPVQOHhqMSi1BHf7GrnqvPnuNAWxTXUaJuEaJCAH3FcRPV8bPNAyBP 97DwoXH4thgZXR0fR9PR1M9LhqQ5Ly0DQOIUI0YJfgcOL2+RomV53tnWFMR9wBS3 9rkxs//B3R1QIKBk1rdF/sAE0weztu/dZ0rQFuyEQ9fuXOMFP2rRGJygOy9ePskw 6Qq67oyHg0fMSWx1g/0FYMCmpxqrK4q5XJZIXfm67DmYUSx5aRV27IAJU+t+B0xQ tQMSMRzrmGlx3ah6O1UF+8mmae9XEPUj1HxBreNJ+NIHY7p9IUcUA30VgVpGyWlZ 13EOqlRYCMe0j2fNuDtf69LaWs+WKf1nqIfFZvCEFcRXJIZt8Ke4I3j3ohUGGIxr pgZ3SNRpdBo6Toka8TAWFyMbwfMWCbbGt8NINqfQIrp0NxOi3kW+wnYx0Mtg6Ugp eHLfsOsakOoQw3z00xYScN//HEKCpcZ2c/WI99BKmpuaVo0a6h40CDT7cx2bTQcQ Glb+ZxzMKDI18GR7NstnNckpei7QoRrSUXSaIODFhivU2zwPmQ0Q7DSII0xaI1F1 P1Oz/hRcWfi6fzQmT3Ao8FolT/vpgZexamC+un81TCVpivYEywtGHHQgEILQgj// +vPFuLJ0YDjONQQQ/yj4zpYgg3zaHizTn4hDRYWc+W0QR4GXzkQ= =02Ei -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds