-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4762-1 [email protected]
https://www.debian.org/lts/security/ Abhijith PA
August 31, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : libarchive
Version : 3.4.3-2+deb11u5 3.6.2-1+deb12u5
CVE ID : CVE-2026-14164 CVE-2026-15028 CVE-2026-16517
Several vulnerabilities were discovered in libarchive, a multi-format
archive and compression library
CVE-2026-14164
A double free issue has been identified in libarchive's RAR5
reader. During parsing of a specially crafted RAR5 archive, the
filtered_buf pointer may remain stale after being freed during
unpacking state reinitialization. Subsequent processing of another
archive entry can trigger a second free of the same memory region,
resulting in a double-free condition. Successful exploitation may
cause applications using the vulnerable libarchive API to
terminate unexpectedly, leading to a denial of service.
CVE-2026-15028
A remote attacker to trigger a heap overflow by providing a
specially crafted tar archive. The issue occurs during the parsing
of a PAX extended header containing a malformed SUN.holesdata
sparse-file attribute. Successful exploitation could lead to a
denial of service, making the system unavailable, or potentially
allow for arbitrary code execution, giving the attacker control
over the affected system.
CVE-2026-16517
A signed integer overflow vulnerability was found in libarchive's
ZIP writer. In the archive_write_zip_header function in
archive_write_set_format_zip.c, when ZIP encryption is enabled and
the entry file size is close to INT64_MAX, the addition of the
encryption overhead to the entry size overflows int64_t, resulting
in undefined behavior. This could lead to incorrect Zip64
extension decisions or potential memory corruption.
For Debian 11 bullseye, these problems have been fixed in version
3.4.3-2+deb11u5.
For Debian 12 bookworm, these problems have been fixed in version
3.6.2-1+deb12u5.
We recommend that you upgrade your libarchive packages.
For the detailed security status of libarchive please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libarchive
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqVLFwACgkQhj1N8u2c
KO9tEA//QQsPVQOHhqMSi1BHf7GrnqvPnuNAWxTXUaJuEaJCAH3FcRPV8bPNAyBP
97DwoXH4thgZXR0fR9PR1M9LhqQ5Ly0DQOIUI0YJfgcOL2+RomV53tnWFMR9wBS3
9rkxs//B3R1QIKBk1rdF/sAE0weztu/dZ0rQFuyEQ9fuXOMFP2rRGJygOy9ePskw
6Qq67oyHg0fMSWx1g/0FYMCmpxqrK4q5XJZIXfm67DmYUSx5aRV27IAJU+t+B0xQ
tQMSMRzrmGlx3ah6O1UF+8mmae9XEPUj1HxBreNJ+NIHY7p9IUcUA30VgVpGyWlZ
13EOqlRYCMe0j2fNuDtf69LaWs+WKf1nqIfFZvCEFcRXJIZt8Ke4I3j3ohUGGIxr
pgZ3SNRpdBo6Toka8TAWFyMbwfMWCbbGt8NINqfQIrp0NxOi3kW+wnYx0Mtg6Ugp
eHLfsOsakOoQw3z00xYScN//HEKCpcZ2c/WI99BKmpuaVo0a6h40CDT7cx2bTQcQ
Glb+ZxzMKDI18GR7NstnNckpei7QoRrSUXSaIODFhivU2zwPmQ0Q7DSII0xaI1F1
P1Oz/hRcWfi6fzQmT3Ao8FolT/vpgZexamC+un81TCVpivYEywtGHHQgEILQgj//
+vPFuLJ0YDjONQQQ/yj4zpYgg3zaHizTn4hDRYWc+W0QR4GXzkQ=
=02Ei
-----END PGP SIGNATURE-----