[CLSA-2026:1786359169] libarchive: Fix of CVE-2026-4424
Type:
security
Severity:
Important
Release date:
2026-08-10 10:53:00 UTC
Description:
- CVE-2026-4424: fix RAR LZSS window size mismatch after PPMd block (heap OOB read)
CVEs fixed:
Updated packages:
  • bsdcpio-3.1.2-14.amzn2.0.6.tuxcare.els8.x86_64.rpm
    sha:26dc6b87ef63bac4ff6b1ea395263d7245d0cac45859eef8055ab7b3ec552c69
  • bsdtar-3.1.2-14.amzn2.0.6.tuxcare.els8.x86_64.rpm
    sha:b179982115a103695c53957bb3b964978ad58aabe4b0ad07c0e59f7fa66eda30
  • libarchive-3.1.2-14.amzn2.0.6.tuxcare.els8.i686.rpm
    sha:6ecdbfa302eb601c7930580d5d5157d5c8efab45520b30ec22e202ebe911cc93
  • libarchive-3.1.2-14.amzn2.0.6.tuxcare.els8.x86_64.rpm
    sha:b3a3d2c1d756c182663144a6b82322179158d0611831d7cd2a0e6032d601fc29
  • libarchive-devel-3.1.2-14.amzn2.0.6.tuxcare.els8.x86_64.rpm
    sha:fe022e3136508e5d51fd06b3582d62ec1b5595e8d0ca508efefc04550a0c6ca7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.