Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93231.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-93231
Upstream
  • CVE-2026-16517
Published
2026-07-21T23:17:00Z
Modified
2026-09-20T05:33:47Z
Summary
CVE-2026-16517 affecting package libarchive 3.7.7-7
Details

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.

References

Affected packages

Azure Linux:3 / libarchive

Package

Name
libarchive
Purl
pkg:rpm/azure-linux/libarchive

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.7.7-7

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93231.json"