[CLSA-2026:1787908647] Fix of 8 CVEs
Type:
security
Severity:
Critical
Release date:
2026-08-28 09:17:42 UTC
Description:
* SECURITY UPDATE: ACLs applied to a symbolic link modified the link target instead - debian/patches/CVE-2021-23177.patch: ACLs applied to a symbolic link modified the link target instead - CVE-2021-23177 * SECURITY UPDATE: symbolic links followed when changing modes, times, ACLs and flags while extracting an archive - debian/patches/CVE-2021-31566.patch: symbolic links followed when changing modes, times, ACLs and flags while extracting an archive - CVE-2021-31566 * SECURITY UPDATE: NULL pointer dereference when calloc() fails while allocating a write filter - debian/patches/CVE-2022-36227.patch: NULL pointer dereference when calloc() fails while allocating a write filter - CVE-2022-36227 * SECURITY UPDATE: integer overflow in the RAR4 reader allowing an oversized memcpy in copy_from_lzss_window() - debian/patches/CVE-2024-20696.patch: integer overflow in the RAR4 reader allowing an oversized memcpy in copy_from_lzss_window() - CVE-2024-20696 * SECURITY UPDATE: LZSS window size mismatch after a PPMd block in the RAR4 reader allowing an out-of-bounds read - debian/patches/CVE-2026-4424.patch: LZSS window size mismatch after a PPMd block in the RAR4 reader allowing an out-of-bounds read - CVE-2026-4424 * SECURITY UPDATE: unvalidated zisofs block size exponent in the ISO9660 Rock Ridge ZF parser - debian/patches/CVE-2026-5121.patch: unvalidated zisofs block size exponent in the ISO9660 Rock Ridge ZF parser - CVE-2026-5121 * SECURITY UPDATE: double free in the RAR4 reader with over 4 billion nodes - debian/patches/CVE-2025-5914.patch: double free in the RAR4 reader with over 4 billion nodes - CVE-2025-5914 * SECURITY UPDATE: unchecked strftime() return and localtime() NULL dereference in the bsdtar verbose listing - debian/patches/CVE-2025-25724.patch: check the strftime() result so a custom locale whose expansion exceeds the 100-byte buffer cannot leave stale content in it, and guard localtime() returning NULL; backports upstream c9bc934e and ecce4674 - CVE-2025-25724 * Guard the RAR seek cursor before the previous-block lookup - debian/patches/rar-guard-seek-cursor.patch: reject a zero cursor in archive_read_format_rar_seek_data() before reading dbo[cursor - 1], which would otherwise underflow; backports upstream e548c994 * Check the ISO9660 ZF entry length before reading its data bytes - debian/patches/iso9660-zf-length-check.patch: test data_length before data[0]/data[1] in parse_rockridge_ZF1(), so a zero-length ZF entry cannot be read past the SUSP region bound; backports upstream a9a73c0e
Updated packages:
  • bsdcpio_3.2.2-3.1ubuntu0.7+tuxcare.els1_all.deb
    sha:9c428dc7ebd50a3f62d3acfc57af8d783397cf67
  • bsdtar_3.2.2-3.1ubuntu0.7+tuxcare.els1_all.deb
    sha:568ca52834b27ca5e5e718394e6a63b1710a4256
  • libarchive-dev_3.2.2-3.1ubuntu0.7+tuxcare.els1_amd64.deb
    sha:7b85c1e42a0b990ace89730bb89440e896fd883d
  • libarchive-tools_3.2.2-3.1ubuntu0.7+tuxcare.els1_amd64.deb
    sha:320278270d951665e11aa79e13ebabbc809dfb95
  • libarchive13_3.2.2-3.1ubuntu0.7+tuxcare.els1_amd64.deb
    sha:f66236953a7083a5976425d84135e6c990a8b992
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.