PT-2026-63256 · Unknown · Libarchive

CVE-2026-16517

·

Published

2026-07-21

·

Updated

2026-08-31

CVSS v3.1

2.9

Low

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions libarchive (affected versions not specified)
Description A signed integer overflow occurs in the ZIP writer. Within the archive write zip header() function in archive write set format zip.c, when ZIP encryption is active and the entry file size is near INT64 MAX, adding encryption overhead to the entry size overflows the int64 t type. This results in undefined behavior, which may lead to memory corruption or incorrect Zip64 extension decisions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-93231
CVE-2026-16517
ECHO-AF27-3CF7-5F51
OESA-2026-3258
RHSA-2026:43818

Affected Products

Libarchive