{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu18.04els/vex/2026/cve-2026-4426-els_os-ubuntu18_04els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-28T12:56:24Z",
      "generator": {
        "date": "2026-08-28T12:56:24Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-4426-ELS_OS-UBUNTU18.04ELS",
      "initial_release_date": "2026-03-19T15:16:00Z",
      "revision_history": [
        {
          "date": "2026-03-19T15:16:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-28T12:56:24Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2026-4426"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 18.04",
                "product": {
                  "name": "Ubuntu 18.04",
                  "product_id": "Ubuntu-18",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libarchive-tools-0:3.2.2-3.1ubuntu0.7.amd64",
                "product": {
                  "name": "libarchive-tools-0:3.2.2-3.1ubuntu0.7.amd64",
                  "product_id": "libarchive-tools-0:3.2.2-3.1ubuntu0.7.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/libarchive-tools@3.2.2-3.1ubuntu0.7?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libarchive13-0:3.2.2-3.1ubuntu0.7.amd64",
                "product": {
                  "name": "libarchive13-0:3.2.2-3.1ubuntu0.7.amd64",
                  "product_id": "libarchive13-0:3.2.2-3.1ubuntu0.7.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/libarchive13@3.2.2-3.1ubuntu0.7?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libarchive-dev-0:3.2.2-3.1ubuntu0.7.amd64",
                "product": {
                  "name": "libarchive-dev-0:3.2.2-3.1ubuntu0.7.amd64",
                  "product_id": "libarchive-dev-0:3.2.2-3.1ubuntu0.7.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/libarchive-dev@3.2.2-3.1ubuntu0.7?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "bsdcpio-0:3.2.2-3.1ubuntu0.7.all",
                "product": {
                  "name": "bsdcpio-0:3.2.2-3.1ubuntu0.7.all",
                  "product_id": "bsdcpio-0:3.2.2-3.1ubuntu0.7.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/bsdcpio@3.2.2-3.1ubuntu0.7?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "bsdtar-0:3.2.2-3.1ubuntu0.7.all",
                "product": {
                  "name": "bsdtar-0:3.2.2-3.1ubuntu0.7.all",
                  "product_id": "bsdtar-0:3.2.2-3.1ubuntu0.7.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/bsdtar@3.2.2-3.1ubuntu0.7?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                "product": {
                  "name": "libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                  "product_id": "libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libarchive-tools@3.2.2-3.1ubuntu0.7%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                "product": {
                  "name": "libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                  "product_id": "libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libarchive13@3.2.2-3.1ubuntu0.7%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                "product": {
                  "name": "libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                  "product_id": "libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libarchive-dev@3.2.2-3.1ubuntu0.7%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
                "product": {
                  "name": "bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
                  "product_id": "bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/bsdcpio@3.2.2-3.1ubuntu0.7%2Btuxcare.els1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
                "product": {
                  "name": "bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
                  "product_id": "bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/bsdtar@3.2.2-3.1ubuntu0.7%2Btuxcare.els1?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
        },
        "product_reference": "libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libarchive-tools-0:3.2.2-3.1ubuntu0.7.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7.amd64"
        },
        "product_reference": "libarchive-tools-0:3.2.2-3.1ubuntu0.7.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
        },
        "product_reference": "libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libarchive13-0:3.2.2-3.1ubuntu0.7.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7.amd64"
        },
        "product_reference": "libarchive13-0:3.2.2-3.1ubuntu0.7.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all"
        },
        "product_reference": "bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "bsdcpio-0:3.2.2-3.1ubuntu0.7.all as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7.all"
        },
        "product_reference": "bsdcpio-0:3.2.2-3.1ubuntu0.7.all",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64"
        },
        "product_reference": "libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libarchive-dev-0:3.2.2-3.1ubuntu0.7.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7.amd64"
        },
        "product_reference": "libarchive-dev-0:3.2.2-3.1ubuntu0.7.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all"
        },
        "product_reference": "bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "bsdtar-0:3.2.2-3.1ubuntu0.7.all as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7.all"
        },
        "product_reference": "bsdtar-0:3.2.2-3.1ubuntu0.7.all",
        "relates_to_product_reference": "Ubuntu-18"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-4426",
      "cwe": {
        "id": "CWE-1335",
        "name": "Incorrect Bitwise Shift of Integer"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7.all",
          "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
          "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7.all",
          "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7.amd64",
          "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7.amd64",
          "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
          "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-4426"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8944",
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-4426",
          "url": "https://access.redhat.com/security/cve/CVE-2026-4426"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2449010",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449010"
        },
        {
          "category": "external",
          "summary": "https://github.com/libarchive/libarchive/pull/2897",
          "url": "https://github.com/libarchive/libarchive/pull/2897"
        }
      ],
      "release_date": "2026-03-19T15:16:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-22T12:11:55.213273Z",
          "details": "This issue only triggers when an application actually parses a crafted ISO9660 image using libarchive’s Rock Ridge zisofs path, which requires explicit user interaction to open or import that file. Its effect is limited to availability (process crash from incorrect allocation) with no confidentiality or integrity impact, and it does not provide code execution or privilege escalation. Because common server and VM workloads do not automatically process ISO images via libarchive, the practical exposure is narrow and the vulnerability can be safely deprioritized.",
          "product_ids": [
            "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7.all",
            "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7.all",
            "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7.amd64",
            "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7.amd64",
            "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:bsdcpio-0:3.2.2-3.1ubuntu0.7.all",
            "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.all",
            "Ubuntu-18:bsdtar-0:3.2.2-3.1ubuntu0.7.all",
            "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive-dev-0:3.2.2-3.1ubuntu0.7.amd64",
            "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive-tools-0:3.2.2-3.1ubuntu0.7.amd64",
            "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7+tuxcare.els1.amd64",
            "Ubuntu-18:libarchive13-0:3.2.2-3.1ubuntu0.7.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}