{"id":"SUSE-SU-2026:23309-1","summary":"Security update for libarchive","details":"This update for libarchive fixes the following issues:\n\n- Fix creation of temporary files in target directory (bsc#1254340)\n- Fix out-of-bounds buffer overrun when using p[H_LEVEL_OFFSET] (bsc#1254341)\n- Fix buffer overrun in archive_le32dec when reading truncated 7zip headers (bsc#1254342)\n- Fix NULL pointer dereference in archive_acl_from_text_w() (bsc#1260998)\n- Fix SEGV in check_7zip_header_in_sfx via ELF offset validation (bsc#1260999)\n- Fix out-of-bounds access on ELF 64-bit header (bsc#1261000)\n- Fix RAR5 memory leak with many filters (bsc#1261002)\n- Fix file descriptor leak in mtree parser cleanup (bsc#1261003)\n","modified":"2026-09-10T18:23:09.579582397Z","published":"2026-08-24T18:51:05Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623309-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254340"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254341"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254342"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260998"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260999"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261000"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261002"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261003"}],"affected":[{"package":{"name":"libarchive","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/libarchive&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.1-160000.4.1"}]}],"ecosystem_specific":{"binaries":[{"libarchive13":"3.8.1-160000.4.1","bsdtar":"3.8.1-160000.4.1","libarchive-devel":"3.8.1-160000.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23309-1.json"}},{"package":{"name":"libarchive","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/libarchive&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.1-160000.4.1"}]}],"ecosystem_specific":{"binaries":[{"libarchive-devel":"3.8.1-160000.4.1","libarchive13":"3.8.1-160000.4.1","bsdtar":"3.8.1-160000.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23309-1.json"}}],"schema_version":"1.9.0"}