USN-8581-1: libarchive vulnerabilities | Ubuntu security notices

It was discovered that libarchive did not properly manage memory when
unpacking certain RAR5 archives, leading to a double free. An attacker
could possibly use this issue to cause a denial of service.
(CVE-2026-14164)

It was discovered that libarchive did not properly validate certain tar
archives, leading to a buffer overflow. A remote attacker could possibly
use this issue to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15028)

It was discovered that libarchive did not properly validate certain
malformed ACL entries. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-5745)

It was discovered that libarchive did not properly manage memory when
unpacking certain RAR5 archives, leading to a double free. An attacker
could possibly use this issue to cause a denial of service.
(CVE-2026-14164)

It was discovered that libarchive did not properly validate certain tar
archives, leading to a buffer overflow. A remote attacker could possibly
use this issue to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15028)

It was discovered that libarchive did not properly validate certain
malformed ACL entries. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-5745)

Scroll to Top