PT-2026-80714 · Suse · Libarchive

Published

2026-08-10

·

Updated

2026-08-10

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This update for libarchive fixes the following issues:
  • creating temporary files in the current working directory instead of the target directory can lead to file creation failures when the working directory is not writable (bsc#1254340).
  • file descriptor leak in the mtree parser cleanup path could lead to file descriptor exhaustion and denial of service (bsc#1261003).
  • NULL pointer dereference in archive acl from text w() could lead to a segmentation fault (bsc#1260998).
  • reading from an invalid index when buffer size is smaller than H LEVEL OFFSET can lead to an out-of-bounds buffer overrun (bsc#1254341).
  • incorrect pointer handling for RAR5 files declaring over 8192 filters can lead to excessive resource usage and denial of service (bsc#1261002)
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

SUSE-SU-2026:23062-1

Affected Products

Libarchive