Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3429-1

Опубликовано: 30 июл. 2026
Источник: suse-cvrf

Описание

Security update for libarchive

This update for libarchive fixes the following issues:

  • creating temporary files in the current working directory instead of the target directory can lead to file creation failures when the working directory is not writable (bsc#1254340).
  • file descriptor leak in the mtree parser cleanup path could lead to file descriptor exhaustion and denial of service (bsc#1261003).
  • NULL pointer dereference in archive_acl_from_text_w() could lead to a segmentation fault (bsc#1260998).
  • reading from an invalid index when buffer size is smaller than H_LEVEL_OFFSET can lead to an out-of-bounds buffer overrun (bsc#1254341).
  • incorrect pointer handling for RAR5 files declaring over 8192 filters can lead to excessive resource usage and denial of service (bsc#1261002).

Список пакетов

Container bci/spack:latest
libarchive13-3.7.2-150600.3.23.1
Container suse/samba-client:latest
libarchive13-3.7.2-150600.3.23.1
Container suse/samba-server:latest
libarchive13-3.7.2-150600.3.23.1
Container suse/samba-toolbox:latest
libarchive13-3.7.2-150600.3.23.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
libarchive-devel-3.7.2-150600.3.23.1
libarchive13-3.7.2-150600.3.23.1
SUSE Linux Enterprise Module for Development Tools 15 SP7
bsdtar-3.7.2-150600.3.23.1