MGASA-2026-0366

Source
https://advisories.mageia.org/MGASA-2026-0366.html
Import Source
https://advisories.mageia.org/MGASA-2026-0366.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0366
Upstream
  • CVE-2026-14164
  • CVE-2026-15028
  • CVE-2026-4424
  • CVE-2026-4426
  • CVE-2026-5121
  • CVE-2026-5745
Published
2026-09-02T16:59:28Z
Modified
2026-09-02T17:11:17.793563615Z
Summary
Updated libarchive packages fix security vulnerabilities
Details

Double-free vulnerability in rar5 decompression logic via dangling filteredbuf pointer in initunpack(). (CVE-2026-14164) Heap overflow oob read while parsing a tar archive contains a pax extended header. (CVE-2026-15028) A null pointer dereference vulnerability exists in the acl parser of libarchive. (CVE-2026-5745) Reading past eof may be triggered for piped file streams. (CVE-2025-5918) An issue was discovered in libarchive bsdtar before version 3.8.1 in function applysubstitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash). (CVE-2025-60753) Infinite loop denial of service in rar5 decompression via archiveread_data() in libarchive. (CVE-2026-4111) Information disclosure via heap out-of-bounds read in rar archive processing. (CVE-2026-4424) Denial of service via malformed iso file processing. (CVE-2026-4426) Arbitrary code execution via integer overflow in iso9660 image processing. (CVE-2026-5121)

References
Credits

Affected packages

Mageia:10 / libarchive

Package

Name
libarchive
Purl
pkg:rpm/mageia/libarchive?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.9-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0366.json"

Mageia:9 / libarchive

Package

Name
libarchive
Purl
pkg:rpm/mageia/libarchive?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.2-5.6.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0366.json"