Search CVE reports


Toggle filters

1 – 10 of 100 results


CVE-2025-64031

Medium priority
Needs evaluation

libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to...

1 affected package

libarchive

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-16517

Medium priority
Needs evaluation

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to...

1 affected package

libarchive

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-15028

Medium priority
Fixed

A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing...

1 affected package

libarchive

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-14164

Medium priority

Some fixes available 4 of 5

A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state...

1 affected package

libarchive

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Fixed Fixed Not affected
Show less packages

CVE-2026-5745

Medium priority

Some fixes available 4 of 5

A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or...

1 affected package

libarchive

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Fixed Fixed Not affected
Show less packages

CVE-2026-5121

Medium priority
Fixed

A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can...

1 affected package

libarchive

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-4426

Medium priority
Fixed

A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can...

1 affected package

libarchive

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-4424

Medium priority
Fixed

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A...

1 affected package

libarchive

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-4111

Medium priority
Fixed

A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine...

1 affected package

libarchive

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-60753

Negligible priority

Some fixes available 7 of 8

An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of...

1 affected package

libarchive

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Fixed Fixed
Show less packages