| Package | libarchive |
|---|---|
| Version | 3.2.2-2+deb9u7 (stretch), 3.3.3-4+deb10u6 (buster) |
| Related CVEs | CVE-2026-4424 CVE-2026-4426 CVE-2026-5121 CVE-2026-15028 CVE-2026-16517 |
Several vulnerabilities were discovered in libarchive, a multi-format archive and compression library
CVE-2026-4424
A flaw was found in libarchive. This heap out-of-bounds read
vulnerability exists in the RAR archive processing logic due to
improper validation of the LZSS sliding window size after transitions
between compression methods. A remote attacker can exploit this by
providing a specially crafted RAR archive, leading to the disclosure
of sensitive heap memory information without requiring authentication
or user interaction.
CVE-2026-4426
A flaw was found in libarchive. An Undefined Behavior vulnerability
exists in the zisofs decompression logic, caused by improper
validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge
extensions. A remote attacker can exploit this by supplying a
specially crafted ISO file. This can lead to incorrect memory
allocation and potential application crashes, resulting in a
denial-of-service (DoS) condition.
CVE-2026-5121
A flaw was found in libarchive. On 32-bit systems, an integer overflow
vulnerability exists in the zisofs block pointer allocation logic. A
remote attacker can exploit this by providing a specially crafted
ISO9660 image, which can lead to a heap buffer overflow. This could
potentially allow for arbitrary code execution on the affected system.
CVE-2026-15028
A remote attacker to trigger a heap overflow by providing a
specially crafted tar archive. The issue occurs during the parsing
of a PAX extended header containing a malformed SUN.holesdata
sparse-file attribute. Successful exploitation could lead to a
denial of service, making the system unavailable, or potentially
allow for arbitrary code execution, giving the attacker control
over the affected system.
CVE-2026-16517
A signed integer overflow vulnerability was found in libarchive's
ZIP writer. In the archive_write_zip_header function in
archive_write_set_format_zip.c, when ZIP encryption is enabled and
the entry file size is close to INT64_MAX, the addition of the
encryption overhead to the entry size overflows int64_t, resulting
in undefined behavior. This could lead to incorrect Zip64
extension decisions or potential memory corruption.
For Debian 10 buster, these problems have been fixed in version 3.3.3-4+deb10u6.
For Debian 9 stretch, these problems have been fixed in version 3.2.2-2+deb9u7.
We recommend that you upgrade your libarchive packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.