← Back

Libarchive

libarchive

Vendor: Libarchive • 76 CVEs

CVEs (76)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Libarchive
1Libarchive
May 13, 2026
Apr 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive file.
2Libarchive
Opensuse
2Leap
Libarchive
May 13, 2026
Feb 15, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (out-of-bounds read) via multiple EmptyStream attributes in a header in a 7zip archi...Show more
The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (out-of-bounds read) via multiple EmptyStream attributes in a header in a 7zip archive.Show less
2Libarchive
Opensuse
2Leap
Libarchive
May 13, 2026
Feb 15, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of service (crash) via a crafted file, which triggers an invalid read...Show more
The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of service (crash) via a crafted file, which triggers an invalid read in the (1) detect_form or (2) bid_entry function in libarchive/archive_read_support_format_mtree.c.Show less
2Libarchive
Opensuse
2Leap
Libarchive
May 13, 2026
Feb 15, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to cause a denial of service via a crafted non-printable multibyte character in a filename.
1Libarchive
1Libarchive
May 13, 2026
Jan 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specia...Show more
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.Show less
3Libarchive
OracleRedhat
9Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+6 more
May 6, 2026
Sep 21, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
2Libarchive
Oracle
2Libarchive
Linux
May 6, 2026
Sep 21, 2016
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when...Show more
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.Show less
3Libarchive
OracleRedhat
10Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+7 more
May 6, 2026
Sep 21, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file.
3Libarchive
OracleRedhat
10Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+7 more
May 6, 2026
Sep 21, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.
3Libarchive
OracleRedhat
9Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+6 more
May 6, 2026
Sep 21, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large...Show more
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large symlink.Show less
2Libarchive
Redhat
8Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+5 more
May 6, 2026
Sep 21, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary.
1Libarchive
1Libarchive
May 6, 2026
Sep 21, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.
2Libarchive
Redhat
8Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+5 more
May 6, 2026
Sep 21, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, w...Show more
Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buffer overflow.Show less
3Canonical
LibarchiveSuse
5Libarchive
Linux Enterprise DesktopLinux Enterprise Server+2 more
May 6, 2026
Sep 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.
3Canonical
LibarchiveSuse
5Libarchive
Linux Enterprise DesktopLinux Enterprise Server+2 more
May 6, 2026
Sep 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file.
4Canonical
DebianLibarchive+1 more
6Debian Linux
LibarchiveLinux Enterprise Desktop+3 more
May 6, 2026
Sep 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left s...Show more
The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.Show less
4Canonical
DebianLibarchive+1 more
6Debian Linux
LibarchiveLinux Enterprise Desktop+3 more
May 6, 2026
Sep 20, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2.0 allow remote attackers to have unspecified impact via a crafted mtre...Show more
Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2.0 allow remote attackers to have unspecified impact via a crafted mtree file, which triggers undefined behavior.Show less
3Canonical
LibarchiveSuse
5Libarchive
Linux Enterprise DesktopLinux Enterprise Server+2 more
May 6, 2026
Sep 20, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a member of itself.
2Libarchive
Suse
4Libarchive
Linux Enterprise DesktopLinux Enterprise Server+1 more
May 6, 2026
Sep 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Memory leak in the __archive_read_get_extract function in archive_read_extract2.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service via a tar file.
3Canonical
LibarchiveSuse
5Libarchive
Linux Enterprise DesktopLinux Enterprise Server+2 more
May 6, 2026
Sep 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.