[ALSA-2026:69553] Low: libarchive security update
Type:
security
Severity:
low
Release date:
2026-09-22
Description:
The libarchive programming library can create and read several different streaming archive formats, including GNU tar, cpio, and ISO 9660 CD-ROM images. Libarchive is used notably in the bsdtar utility, scripting language bindings such as python-libarchive, and several popular desktop file managers. Security Fix(es): * libarchive: heap overflow OOB read while parsing a tar archive contains a PAX extended header (CVE-2026-15028) * libarchive: libarchive: Signed Integer Overflow in archive_write_zip_header (CVE-2026-16517) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 bsdtar-3.7.7-11.el10_2.aarch64.rpm 24f7766155b3e01bfa2872284520a59b0422db9aea74681ea450ff870455709c
aarch64 libarchive-devel-3.7.7-11.el10_2.aarch64.rpm 2ffab48a66c2eaf05ba64398638177da318530e2ae59301166c1d427c475eb77
aarch64 libarchive-3.7.7-11.el10_2.aarch64.rpm a57d86bef7272eddb558e16b16ce48ae1f35c671f82275eab54fa46b0779683b
ppc64le libarchive-devel-3.7.7-11.el10_2.ppc64le.rpm 557cbcf0c544b4661dd5c5c8290bbb4cd0a24b261e160ad6004860172a8fdde0
ppc64le libarchive-3.7.7-11.el10_2.ppc64le.rpm 69bfc0fa5a8635fe83447d69578f001cd99f7b42ce064232723cbc8ec5f41c1b
ppc64le bsdtar-3.7.7-11.el10_2.ppc64le.rpm cc9405e3f01fa655d682c5f273ef59b2bd5edecb08e923ef878f716cc2dd1de9
s390x libarchive-devel-3.7.7-11.el10_2.s390x.rpm 190f346396e8acecf7287d3458d538f369dbecbeec2d01ab297d74af3d28d221
s390x bsdtar-3.7.7-11.el10_2.s390x.rpm 19c2a0320fc5e8be2fa4f727d0ce3b452327a9964c835f3f35003543e373fcc3
s390x libarchive-3.7.7-11.el10_2.s390x.rpm 36c4fbea7106b3c26ce693095f9610195893a1429473957c42d8b5587f1df408
x86_64 bsdtar-3.7.7-11.el10_2.x86_64.rpm 43586c14e199e38d03bc4e92e2c4f156cfe54fdd135b29635232c72f0f2bcec8
x86_64 libarchive-devel-3.7.7-11.el10_2.x86_64.rpm c7709890fd26b59788343b81361993a6d3242074a465d641779196821fc6c3e1
x86_64 libarchive-3.7.7-11.el10_2.x86_64.rpm f803005c2b2f7fc967460e7cc8451f684539a860d536be23dcb5a1a1f1143cb2
x86_64_v2 bsdtar-3.7.7-11.el10_2.x86_64_v2.rpm 1d154b966e77e51713a0d73f1cf6653e0434612e74e1d2ae545644be91ff2581
x86_64_v2 libarchive-3.7.7-11.el10_2.x86_64_v2.rpm 92bbcc0e7db1aee3ab3b3364d50aa29cd55fcb51419a693455b63b01b650579d
x86_64_v2 libarchive-devel-3.7.7-11.el10_2.x86_64_v2.rpm f216da10afe7b41dc9fd389d30ab8e975d1bb88c49db04651caa41b7b98b3253
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.