{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* SECURITY UPDATE: ACLs applied to a symbolic link modified the link\n     target instead\n     - debian/patches/CVE-2021-23177.patch: ACLs applied to a symbolic\n       link modified the link target instead\n     - CVE-2021-23177\n   * SECURITY UPDATE: symbolic links followed when changing modes, times,\n     ACLs and flags while extracting an archive\n     - debian/patches/CVE-2021-31566.patch: symbolic links followed when\n       changing modes, times, ACLs and flags while extracting an archive\n     - CVE-2021-31566\n   * SECURITY UPDATE: NULL pointer dereference when calloc() fails while\n     allocating a write filter\n     - debian/patches/CVE-2022-36227.patch: NULL pointer dereference when\n       calloc() fails while allocating a write filter\n     - CVE-2022-36227\n   * SECURITY UPDATE: integer overflow in the RAR4 reader allowing an\n     oversized memcpy in copy_from_lzss_window()\n     - debian/patches/CVE-2024-20696.patch: integer overflow in the RAR4\n       reader allowing an oversized memcpy in copy_from_lzss_window()\n     - CVE-2024-20696\n   * SECURITY UPDATE: LZSS window size mismatch after a PPMd block in the\n     RAR4 reader allowing an out-of-bounds read\n     - debian/patches/CVE-2026-4424.patch: LZSS window size mismatch\n       after a PPMd block in the RAR4 reader allowing an out-of-bounds\n       read\n     - CVE-2026-4424\n   * SECURITY UPDATE: unvalidated zisofs block size exponent in the ISO9660\n     Rock Ridge ZF parser\n     - debian/patches/CVE-2026-5121.patch: unvalidated zisofs block size\n       exponent in the ISO9660 Rock Ridge ZF parser\n     - CVE-2026-5121\n   * SECURITY UPDATE: double free in the RAR4 reader with over 4 billion\n     nodes\n     - debian/patches/CVE-2025-5914.patch: double free in the RAR4 reader\n       with over 4 billion nodes\n     - CVE-2025-5914\n   * SECURITY UPDATE: unchecked strftime() return and localtime() NULL\n     dereference in the bsdtar verbose listing\n     - debian/patches/CVE-2025-25724.patch: check the strftime() result so a\n       custom locale whose expansion exceeds the 100-byte buffer cannot leave\n       stale content in it, and guard localtime() returning NULL; backports\n       upstream c9bc934e and ecce4674\n     - CVE-2025-25724\n   * Guard the RAR seek cursor before the previous-block lookup\n     - debian/patches/rar-guard-seek-cursor.patch: reject a zero cursor in\n       archive_read_format_rar_seek_data() before reading dbo[cursor - 1],\n       which would otherwise underflow; backports upstream e548c994\n   * Check the ISO9660 ZF entry length before reading its data bytes\n     - debian/patches/iso9660-zf-length-check.patch: test data_length before\n       data[0]/data[1] in parse_rockridge_ZF1(), so a zero-length ZF entry\n       cannot be read past the SUSP region bound; backports upstream a9a73c0e",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu18.04els/advisories/2026/clsa-2026_1787908647.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-28T09:18:50Z",
      "generator": {
        "date": "2026-08-28T09:18:50Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1787908647",
      "initial_release_date": "2026-08-28T09:18:50Z",
      "revision_history": [
        {
          "date": "2026-08-28T09:18:50Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "Fix of 8 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 18.04",
                "product": {
                  "name": "Ubuntu 18.04",
                  "product_id": "Ubuntu-18",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                "product": {
                  "name": "libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                  "product_id": "libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libarchive-tools@3.2.2-3.1ubuntu0.7%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                "product": {
                  "name": "libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                  "product_id": "libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libarchive13@3.2.2-3.1ubuntu0.7%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                "product": {
                  "name": "libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                  "product_id": "libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libarchive-dev@3.2.2-3.1ubuntu0.7%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
                "product": {
                  "name": "bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
                  "product_id": "bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/bsdcpio@3.2.2-3.1ubuntu0.7%2Btuxcare.els1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
                "product": {
                  "name": "bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
                  "product_id": "bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/bsdtar@3.2.2-3.1ubuntu0.7%2Btuxcare.els1?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
        },
        "product_reference": "libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
        },
        "product_reference": "libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all"
        },
        "product_reference": "bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
        },
        "product_reference": "libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all"
        },
        "product_reference": "bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
        "relates_to_product_reference": "Ubuntu-18"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-5914",
      "cwe": {
        "id": "CWE-190",
        "name": "Integer Overflow or Wraparound"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-5914"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:14130",
          "url": "https://access.redhat.com/errata/RHSA-2025:14130"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:14135",
          "url": "https://access.redhat.com/errata/RHSA-2025:14135"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:14137",
          "url": "https://access.redhat.com/errata/RHSA-2025:14137"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:14141",
          "url": "https://access.redhat.com/errata/RHSA-2025:14141"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:14142",
          "url": "https://access.redhat.com/errata/RHSA-2025:14142"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:14525",
          "url": "https://access.redhat.com/errata/RHSA-2025:14525"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:14528",
          "url": "https://access.redhat.com/errata/RHSA-2025:14528"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:14594",
          "url": "https://access.redhat.com/errata/RHSA-2025:14594"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:14644",
          "url": "https://access.redhat.com/errata/RHSA-2025:14644"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:14808",
          "url": "https://access.redhat.com/errata/RHSA-2025:14808"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:14810",
          "url": "https://access.redhat.com/errata/RHSA-2025:14810"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:14828",
          "url": "https://access.redhat.com/errata/RHSA-2025:14828"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:15024",
          "url": "https://access.redhat.com/errata/RHSA-2025:15024"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:15397",
          "url": "https://access.redhat.com/errata/RHSA-2025:15397"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:15709",
          "url": "https://access.redhat.com/errata/RHSA-2025:15709"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:15827",
          "url": "https://access.redhat.com/errata/RHSA-2025:15827"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:15828",
          "url": "https://access.redhat.com/errata/RHSA-2025:15828"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:16524",
          "url": "https://access.redhat.com/errata/RHSA-2025:16524"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:18217",
          "url": "https://access.redhat.com/errata/RHSA-2025:18217"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:18218",
          "url": "https://access.redhat.com/errata/RHSA-2025:18218"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:18219",
          "url": "https://access.redhat.com/errata/RHSA-2025:18219"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:19041",
          "url": "https://access.redhat.com/errata/RHSA-2025:19041"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:19046",
          "url": "https://access.redhat.com/errata/RHSA-2025:19046"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:21885",
          "url": "https://access.redhat.com/errata/RHSA-2025:21885"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:21913",
          "url": "https://access.redhat.com/errata/RHSA-2025:21913"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:0326",
          "url": "https://access.redhat.com/errata/RHSA-2026:0326"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:0934",
          "url": "https://access.redhat.com/errata/RHSA-2026:0934"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:1541",
          "url": "https://access.redhat.com/errata/RHSA-2026:1541"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2025-5914",
          "url": "https://access.redhat.com/security/cve/CVE-2025-5914"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2370861",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370861"
        },
        {
          "category": "external",
          "summary": "https://github.com/libarchive/libarchive/pull/2598",
          "url": "https://github.com/libarchive/libarchive/pull/2598"
        },
        {
          "category": "external",
          "summary": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0",
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "category": "external",
          "summary": "https://cert-portal.siemens.com/productcert/html/ssa-585531.html",
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-585531.html"
        }
      ],
      "release_date": "2025-06-09T20:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-28T09:17:29.819251Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647",
          "product_ids": [
            "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2021-31566",
      "cwe": {
        "id": "CWE-59",
        "name": "Improper Link Resolution Before File Access ('Link Following')"
      },
      "notes": [
        {
          "category": "description",
          "text": "An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a system.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2021-31566"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2021-31566",
          "url": "https://access.redhat.com/security/cve/CVE-2021-31566"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2024237",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2024237"
        },
        {
          "category": "external",
          "summary": "https://github.com/libarchive/libarchive/commit/b41daecb5ccb4c8e3b2c53fd6147109fc12c3043",
          "url": "https://github.com/libarchive/libarchive/commit/b41daecb5ccb4c8e3b2c53fd6147109fc12c3043"
        },
        {
          "category": "external",
          "summary": "https://github.com/libarchive/libarchive/issues/1566",
          "url": "https://github.com/libarchive/libarchive/issues/1566"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2022/11/msg00030.html",
          "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00030.html"
        }
      ],
      "release_date": "2022-08-23T16:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-28T09:17:29.819251Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647",
          "product_ids": [
            "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-20696",
      "cwe": {
        "id": "CWE-122",
        "name": "Heap-based Buffer Overflow"
      },
      "notes": [
        {
          "category": "description",
          "text": "Windows libarchive Remote Code Execution Vulnerability",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2024-20696"
        },
        {
          "category": "external",
          "summary": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20696",
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20696"
        },
        {
          "category": "external",
          "summary": "https://clearbluejar.github.io/posts/patch-tuesday-diffing-cve-2024-20696-windows-libarchive-rce/",
          "url": "https://clearbluejar.github.io/posts/patch-tuesday-diffing-cve-2024-20696-windows-libarchive-rce/"
        },
        {
          "category": "external",
          "summary": "https://github.com/clearbluejar/CVE-2024-20696",
          "url": "https://github.com/clearbluejar/CVE-2024-20696"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/11/msg00007.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00007.html"
        }
      ],
      "release_date": "2024-01-09T18:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-28T09:17:29.819251Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647",
          "product_ids": [
            "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2021-23177",
      "cwe": {
        "id": "CWE-59",
        "name": "Improper Link Resolution Before File Access ('Link Following')"
      },
      "notes": [
        {
          "category": "description",
          "text": "An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2021-23177"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2021-23177",
          "url": "https://access.redhat.com/security/cve/CVE-2021-23177"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2024245",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2024245"
        },
        {
          "category": "external",
          "summary": "https://github.com/libarchive/libarchive/commit/fba4f123cc456d2b2538f811bb831483bf336bad",
          "url": "https://github.com/libarchive/libarchive/commit/fba4f123cc456d2b2538f811bb831483bf336bad"
        },
        {
          "category": "external",
          "summary": "https://github.com/libarchive/libarchive/issues/1565",
          "url": "https://github.com/libarchive/libarchive/issues/1565"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2022/11/msg00030.html",
          "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00030.html"
        }
      ],
      "release_date": "2022-08-23T16:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-28T09:17:29.819251Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647",
          "product_ids": [
            "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-5121",
      "cwe": {
        "id": "CWE-190",
        "name": "Integer Overflow or Wraparound"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-5121"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10065",
          "url": "https://access.redhat.com/errata/RHSA-2026:10065"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10097",
          "url": "https://access.redhat.com/errata/RHSA-2026:10097"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:11768",
          "url": "https://access.redhat.com/errata/RHSA-2026:11768"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:12071",
          "url": "https://access.redhat.com/errata/RHSA-2026:12071"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:12274",
          "url": "https://access.redhat.com/errata/RHSA-2026:12274"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13812",
          "url": "https://access.redhat.com/errata/RHSA-2026:13812"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14773",
          "url": "https://access.redhat.com/errata/RHSA-2026:14773"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14937",
          "url": "https://access.redhat.com/errata/RHSA-2026:14937"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:15087",
          "url": "https://access.redhat.com/errata/RHSA-2026:15087"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16008",
          "url": "https://access.redhat.com/errata/RHSA-2026:16008"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16009",
          "url": "https://access.redhat.com/errata/RHSA-2026:16009"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16030",
          "url": "https://access.redhat.com/errata/RHSA-2026:16030"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16174",
          "url": "https://access.redhat.com/errata/RHSA-2026:16174"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:17596",
          "url": "https://access.redhat.com/errata/RHSA-2026:17596"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19724",
          "url": "https://access.redhat.com/errata/RHSA-2026:19724"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19725",
          "url": "https://access.redhat.com/errata/RHSA-2026:19725"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:20040",
          "url": "https://access.redhat.com/errata/RHSA-2026:20040"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:21690",
          "url": "https://access.redhat.com/errata/RHSA-2026:21690"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:25096",
          "url": "https://access.redhat.com/errata/RHSA-2026:25096"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8510",
          "url": "https://access.redhat.com/errata/RHSA-2026:8510"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8517",
          "url": "https://access.redhat.com/errata/RHSA-2026:8517"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8521",
          "url": "https://access.redhat.com/errata/RHSA-2026:8521"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8534",
          "url": "https://access.redhat.com/errata/RHSA-2026:8534"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8864",
          "url": "https://access.redhat.com/errata/RHSA-2026:8864"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8866",
          "url": "https://access.redhat.com/errata/RHSA-2026:8866"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8867",
          "url": "https://access.redhat.com/errata/RHSA-2026:8867"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8873",
          "url": "https://access.redhat.com/errata/RHSA-2026:8873"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8908",
          "url": "https://access.redhat.com/errata/RHSA-2026:8908"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8944",
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:9026",
          "url": "https://access.redhat.com/errata/RHSA-2026:9026"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:9592",
          "url": "https://access.redhat.com/errata/RHSA-2026:9592"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:9832",
          "url": "https://access.redhat.com/errata/RHSA-2026:9832"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-5121",
          "url": "https://access.redhat.com/security/cve/CVE-2026-5121"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2452945",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452945"
        },
        {
          "category": "external",
          "summary": "https://github.com/advisories/GHSA-2vwv-vqpv-v8vc",
          "url": "https://github.com/advisories/GHSA-2vwv-vqpv-v8vc"
        },
        {
          "category": "external",
          "summary": "https://github.com/libarchive/libarchive/pull/2934",
          "url": "https://github.com/libarchive/libarchive/pull/2934"
        },
        {
          "category": "external",
          "summary": "https://cert-portal.siemens.com/productcert/html/ssa-585531.html",
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-585531.html"
        }
      ],
      "release_date": "2026-03-30T08:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-28T09:17:29.819251Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647",
          "product_ids": [
            "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-25724",
      "cwe": {
        "id": "CWE-252",
        "name": "Unchecked Return Value"
      },
      "notes": [
        {
          "category": "description",
          "text": "list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-25724"
        },
        {
          "category": "external",
          "summary": "https://gist.github.com/Ekkosun/a83870ce7f3b7813b9b462a395e8ad92",
          "url": "https://gist.github.com/Ekkosun/a83870ce7f3b7813b9b462a395e8ad92"
        },
        {
          "category": "external",
          "summary": "https://github.com/Ekkosun/pocs/blob/main/bsdtarbug",
          "url": "https://github.com/Ekkosun/pocs/blob/main/bsdtarbug"
        },
        {
          "category": "external",
          "summary": "https://github.com/libarchive/libarchive/blob/b439d586f53911c84be5e380445a8a259e19114c/tar/util.c#L751-L752",
          "url": "https://github.com/libarchive/libarchive/blob/b439d586f53911c84be5e380445a8a259e19114c/tar/util.c#L751-L752"
        }
      ],
      "release_date": "2025-03-02T02:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-28T09:17:29.819251Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647",
          "product_ids": [
            "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2022-36227",
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "notes": [
        {
          "category": "description",
          "text": "In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: \"In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution.\"",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2022-36227"
        },
        {
          "category": "external",
          "summary": "https://bugs.gentoo.org/882521",
          "url": "https://bugs.gentoo.org/882521"
        },
        {
          "category": "external",
          "summary": "https://github.com/libarchive/libarchive/blob/v3.0.0a/libarchive/archive_write.c#L215",
          "url": "https://github.com/libarchive/libarchive/blob/v3.0.0a/libarchive/archive_write.c#L215"
        },
        {
          "category": "external",
          "summary": "https://github.com/libarchive/libarchive/issues/1754",
          "url": "https://github.com/libarchive/libarchive/issues/1754"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/01/msg00034.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/01/msg00034.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V67OO2UUQAUJS3IK4JZPF6F3LUCBU6IS/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V67OO2UUQAUJS3IK4JZPF6F3LUCBU6IS/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202309-14",
          "url": "https://security.gentoo.org/glsa/202309-14"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/11/msg00007.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00007.html"
        }
      ],
      "release_date": "2022-11-22T02:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-28T09:17:29.819251Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647",
          "product_ids": [
            "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2026-4424",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-4424"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10065",
          "url": "https://access.redhat.com/errata/RHSA-2026:10065"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10097",
          "url": "https://access.redhat.com/errata/RHSA-2026:10097"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:11768",
          "url": "https://access.redhat.com/errata/RHSA-2026:11768"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:12071",
          "url": "https://access.redhat.com/errata/RHSA-2026:12071"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:12274",
          "url": "https://access.redhat.com/errata/RHSA-2026:12274"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13812",
          "url": "https://access.redhat.com/errata/RHSA-2026:13812"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14773",
          "url": "https://access.redhat.com/errata/RHSA-2026:14773"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14937",
          "url": "https://access.redhat.com/errata/RHSA-2026:14937"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:15087",
          "url": "https://access.redhat.com/errata/RHSA-2026:15087"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16008",
          "url": "https://access.redhat.com/errata/RHSA-2026:16008"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16009",
          "url": "https://access.redhat.com/errata/RHSA-2026:16009"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16030",
          "url": "https://access.redhat.com/errata/RHSA-2026:16030"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16174",
          "url": "https://access.redhat.com/errata/RHSA-2026:16174"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:17596",
          "url": "https://access.redhat.com/errata/RHSA-2026:17596"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19724",
          "url": "https://access.redhat.com/errata/RHSA-2026:19724"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19725",
          "url": "https://access.redhat.com/errata/RHSA-2026:19725"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:20040",
          "url": "https://access.redhat.com/errata/RHSA-2026:20040"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:21690",
          "url": "https://access.redhat.com/errata/RHSA-2026:21690"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:25096",
          "url": "https://access.redhat.com/errata/RHSA-2026:25096"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8492",
          "url": "https://access.redhat.com/errata/RHSA-2026:8492"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8510",
          "url": "https://access.redhat.com/errata/RHSA-2026:8510"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8517",
          "url": "https://access.redhat.com/errata/RHSA-2026:8517"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8521",
          "url": "https://access.redhat.com/errata/RHSA-2026:8521"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8534",
          "url": "https://access.redhat.com/errata/RHSA-2026:8534"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8864",
          "url": "https://access.redhat.com/errata/RHSA-2026:8864"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8865",
          "url": "https://access.redhat.com/errata/RHSA-2026:8865"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8866",
          "url": "https://access.redhat.com/errata/RHSA-2026:8866"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8867",
          "url": "https://access.redhat.com/errata/RHSA-2026:8867"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8873",
          "url": "https://access.redhat.com/errata/RHSA-2026:8873"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8908",
          "url": "https://access.redhat.com/errata/RHSA-2026:8908"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8944",
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:9026",
          "url": "https://access.redhat.com/errata/RHSA-2026:9026"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:9592",
          "url": "https://access.redhat.com/errata/RHSA-2026:9592"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:9832",
          "url": "https://access.redhat.com/errata/RHSA-2026:9832"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-4424",
          "url": "https://access.redhat.com/security/cve/CVE-2026-4424"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2449006",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449006"
        },
        {
          "category": "external",
          "summary": "https://github.com/libarchive/libarchive/pull/2898",
          "url": "https://github.com/libarchive/libarchive/pull/2898"
        },
        {
          "category": "external",
          "summary": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4424.json",
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4424.json"
        }
      ],
      "release_date": "2026-03-19T15:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-28T09:17:29.819251Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647",
          "product_ids": [
            "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787908647"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}