Описание
Security update for libarchive
This update for libarchive fixes the following issues:
- creating temporary files in the current working directory instead of the target directory can lead to file creation failures when the working directory is not writable (bsc#1254340).
- file descriptor leak in the mtree parser cleanup path could lead to file descriptor exhaustion and denial of service (bsc#1261003).
- NULL pointer dereference in archive_acl_from_text_w() could lead to a segmentation fault (bsc#1260998).
- reading from an invalid index when buffer size is smaller than H_LEVEL_OFFSET can lead to an out-of-bounds buffer overrun (bsc#1254341).
- incorrect pointer handling for RAR5 files declaring over 8192 filters can lead to excessive resource usage and denial of service (bsc#1261002).
Список пакетов
Container bci/spack:latest
libarchive13-3.7.2-150600.3.23.1
Container suse/samba-client:latest
libarchive13-3.7.2-150600.3.23.1
Container suse/samba-server:latest
libarchive13-3.7.2-150600.3.23.1
Container suse/samba-toolbox:latest
libarchive13-3.7.2-150600.3.23.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
libarchive-devel-3.7.2-150600.3.23.1
libarchive13-3.7.2-150600.3.23.1
SUSE Linux Enterprise Module for Development Tools 15 SP7
bsdtar-3.7.2-150600.3.23.1
Ссылки
- Link for SUSE-SU-2026:3429-1
- E-Mail link for SUSE-SU-2026:3429-1
- SUSE Security Ratings
- SUSE Bug 1254340
- SUSE Bug 1254341
- SUSE Bug 1260998
- SUSE Bug 1261002
- SUSE Bug 1261003