PT-2026-63256 · Unknown · Libarchive
CVE-2026-16517
·
Published
2026-07-21
·
Updated
2026-08-31
CVSS v3.1
2.9
Low
| Vector | AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
libarchive (affected versions not specified)
Description
A signed integer overflow occurs in the ZIP writer. Within the
archive write zip header() function in archive write set format zip.c, when ZIP encryption is active and the entry file size is near INT64 MAX, adding encryption overhead to the entry size overflows the int64 t type. This results in undefined behavior, which may lead to memory corruption or incorrect Zip64 extension decisions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libarchive