{"id":"openSUSE-SU-2026:21631-1","summary":"Security update for libarchive","details":"This update for libarchive fixes the following issues:\n\n- Fix creation of temporary files in target directory (bsc#1254340)\n- Fix out-of-bounds buffer overrun when using p[H_LEVEL_OFFSET] (bsc#1254341)\n- Fix buffer overrun in archive_le32dec when reading truncated 7zip headers (bsc#1254342)\n- Fix NULL pointer dereference in archive_acl_from_text_w() (bsc#1260998)\n- Fix SEGV in check_7zip_header_in_sfx via ELF offset validation (bsc#1260999)\n- Fix out-of-bounds access on ELF 64-bit header (bsc#1261000)\n- Fix RAR5 memory leak with many filters (bsc#1261002)\n- Fix file descriptor leak in mtree parser cleanup (bsc#1261003)\n","modified":"2026-08-27T18:23:12.578779207Z","published":"2026-08-24T18:49:00Z","references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254340"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254341"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254342"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260998"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260999"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261000"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261002"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261003"}],"affected":[{"package":{"name":"libarchive","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/libarchive&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.1-160000.4.1"}]}],"ecosystem_specific":{"binaries":[{"bsdtar":"3.8.1-160000.4.1","libarchive-devel":"3.8.1-160000.4.1","libarchive13":"3.8.1-160000.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21631-1.json"}}],"schema_version":"1.9.0"}