CVEs (76)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Libarchive Redhat4Enterprise Linux Hardened ImagesLibarchive+1 moreJun 17, 2026 Apr 7, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bar...Show more |
2Libarchive Redhat4Enterprise Linux Hardened ImagesLibarchive+1 moreJul 14, 2026 Mar 30, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image,...Show more |
2Libarchive Redhat4Enterprise Linux Hardened ImagesLibarchive+1 moreJun 17, 2026 Mar 19, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote atta...Show more |
2Libarchive Redhat7Enterprise Linux Enterprise Linux Server AusHardened Images+4 moreJul 15, 2026 Mar 19, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression metho...Show more |
An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to d...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJun 30, 2026 Jun 9, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can le...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJun 30, 2026 Jun 9, 2025 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seeming...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJun 30, 2026 Jun 9, 2025 N/A· v4 5.6 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content by...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJun 30, 2026 Jun 9, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This mean...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJul 21, 2026 Jun 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condit...Show more |
Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8. |
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose...Show more |
A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to lau...Show more |
execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst. |
execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst. |
Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c. |
3Fedoraproject LibarchiveMicrosoft5Fedora LibarchiveWindows 11 22h2+2 moreJun 17, 2026 Apr 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Libarchive Remote Code Execution Vulnerability |
Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race conditi...Show more |
4Debian FedoraprojectLibarchive+1 more4Debian Linux FedoraLibarchive+1 moreJun 17, 2026 Nov 22, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the...Show more |
5Debian FedoraprojectLibarchive+2 more14Codeready Linux Builder Debian LinuxEnterprise Linux+11 moreJun 17, 2026 Aug 23, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a...Show more |