Advisories ยป MGASA-2026-0366

Updated libarchive packages fix security vulnerabilities

Publication date: 02 Sep 2026
Modification date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14164 , CVE-2026-15028 , CVE-2026-5745 , CVE-2025-5918 , CVE-2025-60753 , CVE-2026-4111 , CVE-2026-4424 , CVE-2026-4426 , CVE-2026-5121

Description

Double-free vulnerability in rar5 decompression logic via dangling
filtered_buf pointer in init_unpack(). (CVE-2026-14164)
Heap overflow oob read while parsing a tar archive contains a pax
extended header. (CVE-2026-15028)
A null pointer dereference vulnerability exists in the acl parser of
libarchive. (CVE-2026-5745)
Reading past eof may be triggered for piped file streams.
(CVE-2025-5918)
An issue was discovered in libarchive bsdtar before version 3.8.1 in
function apply_substitution in file tar/subst.c when processing crafted
-s substitution rules. This can cause unbounded memory allocation and
lead to denial of service (Out-of-Memory crash). (CVE-2025-60753)
Infinite loop denial of service in rar5 decompression via
archive_read_data() in libarchive. (CVE-2026-4111)
Information disclosure via heap out-of-bounds read in rar archive
processing. (CVE-2026-4424)
Denial of service via malformed iso file processing. (CVE-2026-4426)
Arbitrary code execution via integer overflow in iso9660 image
processing. (CVE-2026-5121)
                

References

SRPMS

10/core

9/core