PT-2026-80714 · Suse · Libarchive
Published
2026-08-10
·
Updated
2026-08-10
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This update for libarchive fixes the following issues:
- creating temporary files in the current working directory instead of the target directory can lead to file creation failures when the working directory is not writable (bsc#1254340).
- file descriptor leak in the mtree parser cleanup path could lead to file descriptor exhaustion and denial of service (bsc#1261003).
- NULL pointer dereference in archive acl from text w() could lead to a segmentation fault (bsc#1260998).
- reading from an invalid index when buffer size is smaller than H LEVEL OFFSET can lead to an out-of-bounds buffer overrun (bsc#1254341).
- incorrect pointer handling for RAR5 files declaring over 8192 filters can lead to excessive resource usage and denial of service (bsc#1261002)
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libarchive