Updated libarchive packages fix security vulnerabilities
Publication date: 02 Sep 2026Modification date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14164 , CVE-2026-15028 , CVE-2026-5745 , CVE-2025-5918 , CVE-2025-60753 , CVE-2026-4111 , CVE-2026-4424 , CVE-2026-4426 , CVE-2026-5121
Description
Double-free vulnerability in rar5 decompression logic via dangling
filtered_buf pointer in init_unpack(). (CVE-2026-14164)
Heap overflow oob read while parsing a tar archive contains a pax
extended header. (CVE-2026-15028)
A null pointer dereference vulnerability exists in the acl parser of
libarchive. (CVE-2026-5745)
Reading past eof may be triggered for piped file streams.
(CVE-2025-5918)
An issue was discovered in libarchive bsdtar before version 3.8.1 in
function apply_substitution in file tar/subst.c when processing crafted
-s substitution rules. This can cause unbounded memory allocation and
lead to denial of service (Out-of-Memory crash). (CVE-2025-60753)
Infinite loop denial of service in rar5 decompression via
archive_read_data() in libarchive. (CVE-2026-4111)
Information disclosure via heap out-of-bounds read in rar archive
processing. (CVE-2026-4424)
Denial of service via malformed iso file processing. (CVE-2026-4426)
Arbitrary code execution via integer overflow in iso9660 image
processing. (CVE-2026-5121)
References
- https://bugs.mageia.org/show_bug.cgi?id=35999
- https://ubuntu.com/security/notices/USN-8581-1
- https://www.cve.org/CVERecord?id=CVE-2026-14164
- https://www.cve.org/CVERecord?id=CVE-2026-15028
- https://www.cve.org/CVERecord?id=CVE-2026-5745
- https://www.cve.org/CVERecord?id=CVE-2025-5918
- https://www.cve.org/CVERecord?id=CVE-2025-60753
- https://www.cve.org/CVERecord?id=CVE-2026-4111
- https://www.cve.org/CVERecord?id=CVE-2026-4424
- https://www.cve.org/CVERecord?id=CVE-2026-4426
- https://www.cve.org/CVERecord?id=CVE-2026-5121
SRPMS
10/core
- libarchive-3.8.9-1.mga10
9/core
- libarchive-3.6.2-5.6.mga9