Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2490-1

Опубликовано: 22 июн. 2026
Источник: suse-cvrf

Описание

Security update for libarchive

This update for libarchive fixes the following issues

  • CVE-2025-60753: bsdtar hangs and OOMs with zero-length pattern matches (bsc#1253088).
  • CVE-2026-4111: logical deadlock the RAR5 filter subsystem and the half-window output limiter leads to infinite loop and DoS (bsc#1259635).
  • CVE-2026-4424: information disclosure via heap out-of-bounds read in RAR archive processing (bsc#1259928).
  • CVE-2026-4426: undefined behavior due to unvalidated operand in shift expression of the zisofs decompression code (bsc#1259931).
  • CVE-2026-5121: arbitrary code execution via integer overflow in ISO9660 image processing (bsc#1261186).

Список пакетов

Container bci/spack:latest
libarchive13-3.7.2-150600.3.20.1
Container suse/samba-client:latest
libarchive13-3.7.2-150600.3.20.1
Container suse/samba-server:latest
libarchive13-3.7.2-150600.3.20.1
Container suse/samba-toolbox:latest
libarchive13-3.7.2-150600.3.20.1
Image SLES15-SP7-SAPCAL-Azure
libarchive13-3.7.2-150600.3.20.1
Image SLES15-SP7-SAPCAL-EC2
libarchive13-3.7.2-150600.3.20.1
Image SLES15-SP7-SAPCAL-GCE
libarchive13-3.7.2-150600.3.20.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
libarchive-devel-3.7.2-150600.3.20.1
libarchive13-3.7.2-150600.3.20.1
SUSE Linux Enterprise Module for Development Tools 15 SP7
bsdtar-3.7.2-150600.3.20.1
SUSE Linux Enterprise Server 15 SP6-LTSS
bsdtar-3.7.2-150600.3.20.1
libarchive-devel-3.7.2-150600.3.20.1
libarchive13-3.7.2-150600.3.20.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
bsdtar-3.7.2-150600.3.20.1
libarchive-devel-3.7.2-150600.3.20.1
libarchive13-3.7.2-150600.3.20.1

Описание

An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).


Затронутые продукты
Container bci/spack:latest:libarchive13-3.7.2-150600.3.20.1
Container suse/samba-client:latest:libarchive13-3.7.2-150600.3.20.1
Container suse/samba-server:latest:libarchive13-3.7.2-150600.3.20.1
Container suse/samba-toolbox:latest:libarchive13-3.7.2-150600.3.20.1

Ссылки

Описание

A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.


Затронутые продукты
Container bci/spack:latest:libarchive13-3.7.2-150600.3.20.1
Container suse/samba-client:latest:libarchive13-3.7.2-150600.3.20.1
Container suse/samba-server:latest:libarchive13-3.7.2-150600.3.20.1
Container suse/samba-toolbox:latest:libarchive13-3.7.2-150600.3.20.1

Ссылки

Описание

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.


Затронутые продукты
Container bci/spack:latest:libarchive13-3.7.2-150600.3.20.1
Container suse/samba-client:latest:libarchive13-3.7.2-150600.3.20.1
Container suse/samba-server:latest:libarchive13-3.7.2-150600.3.20.1
Container suse/samba-toolbox:latest:libarchive13-3.7.2-150600.3.20.1

Ссылки

Описание

A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.


Затронутые продукты
Container bci/spack:latest:libarchive13-3.7.2-150600.3.20.1
Container suse/samba-client:latest:libarchive13-3.7.2-150600.3.20.1
Container suse/samba-server:latest:libarchive13-3.7.2-150600.3.20.1
Container suse/samba-toolbox:latest:libarchive13-3.7.2-150600.3.20.1

Ссылки

Описание

A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.


Затронутые продукты
Container bci/spack:latest:libarchive13-3.7.2-150600.3.20.1
Container suse/samba-client:latest:libarchive13-3.7.2-150600.3.20.1
Container suse/samba-server:latest:libarchive13-3.7.2-150600.3.20.1
Container suse/samba-toolbox:latest:libarchive13-3.7.2-150600.3.20.1

Ссылки
Уязвимость SUSE-SU-2026:2490-1