{"id":"MGASA-2026-0366","summary":"Updated libarchive packages fix security vulnerabilities","details":"Double-free vulnerability in rar5 decompression logic via dangling\nfiltered_buf pointer in init_unpack(). (CVE-2026-14164)\nHeap overflow oob read while parsing a tar archive contains a pax\nextended header. (CVE-2026-15028)\nA null pointer dereference vulnerability exists in the acl parser of\nlibarchive. (CVE-2026-5745)\nReading past eof may be triggered for piped file streams.\n(CVE-2025-5918)\nAn issue was discovered in libarchive bsdtar before version 3.8.1 in\nfunction apply_substitution in file tar/subst.c when processing crafted\n-s substitution rules. This can cause unbounded memory allocation and\nlead to denial of service (Out-of-Memory crash). (CVE-2025-60753)\nInfinite loop denial of service in rar5 decompression via\narchive_read_data() in libarchive. (CVE-2026-4111)\nInformation disclosure via heap out-of-bounds read in rar archive\nprocessing. (CVE-2026-4424)\nDenial of service via malformed iso file processing. (CVE-2026-4426)\nArbitrary code execution via integer overflow in iso9660 image\nprocessing. (CVE-2026-5121)\n","modified":"2026-09-02T17:11:17.793563615Z","published":"2026-09-02T16:59:28Z","upstream":["CVE-2025-5918","CVE-2025-60753","CVE-2026-14164","CVE-2026-15028","CVE-2026-4111","CVE-2026-4424","CVE-2026-4426","CVE-2026-5121","CVE-2026-5745"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0366.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35999"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8581-1"}],"affected":[{"package":{"name":"libarchive","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/libarchive?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.9-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0366.json"}},{"package":{"name":"libarchive","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/libarchive?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.2-5.6.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0366.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}