Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93231.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-93231
Upstream
  • CVE-2026-16517
Published
2026-07-21T23:17:00Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-16517 affecting package libarchive 3.7.7-7
Details

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archivewritezipheader function in archivewritesetformatzip.c, when ZIP encryption is enabled and the entry file size is close to INT64MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.

References

Affected packages

Azure Linux:3 / libarchive

Package

Name
libarchive
Purl
pkg:rpm/azure-linux/libarchive

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.7.7-7

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93231.json"