USN-8292-1: libarchive vulnerabilities

Publication date

21 May 2026

Overview

Several security issues were fixed in libarchive.


Packages

  • libarchive - Library to read/write archive files

Details

It was discovered that libarchive incorrectly handled certain RAR
archives. An attacker could possibly use this issue to cause an
out-of-bounds read via a crafted RAR archive, leading to sensitive
memory disclosure. (CVE-2026-4424)

It was discovered that libarchive incorrectly handled certain ISO files.
An attacker could possibly use this issue to cause incorrect memory
allocation via a crafted ISO file, leading to a denial of service.
(CVE-2026-4426)

It was discovered that libarchive incorrectly handled block pointer
allocation in zisofs on 32-bit systems. An attacker could possibly use
this issue to cause a heap buffer overflow via a crafted ISO9660 image,
possibly leading to arbitrary code execution. (CVE-2026-5121)

It was discovered that libarchive incorrectly handled certain RAR
archives. An attacker could possibly use this issue to cause an
out-of-bounds read via a crafted RAR archive, leading to sensitive
memory disclosure. (CVE-2026-4424)

It was discovered that libarchive incorrectly handled certain ISO files.
An attacker could possibly use this issue to cause incorrect memory
allocation via a crafted ISO file, leading to a denial of service.
(CVE-2026-4426)

It was discovered that libarchive incorrectly handled block pointer
allocation in zisofs on 32-bit systems. An attacker could possibly use
this issue to cause a heap buffer overflow via a crafted ISO9660 image,
possibly leading to arbitrary code execution. (CVE-2026-5121)

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute libarchive-dev –  3.8.5-1ubuntu2.1
libarchive-tools –  3.8.5-1ubuntu2.1
libarchive13t64 –  3.8.5-1ubuntu2.1
25.10 questing libarchive-dev –  3.7.7-0ubuntu3.2
libarchive-tools –  3.7.7-0ubuntu3.2
libarchive13t64 –  3.7.7-0ubuntu3.2
24.04 LTS noble libarchive-dev –  3.7.2-2ubuntu0.7
libarchive-tools –  3.7.2-2ubuntu0.7
libarchive13t64 –  3.7.2-2ubuntu0.7
22.04 LTS jammy libarchive-dev –  3.6.0-1ubuntu1.7
libarchive-tools –  3.6.0-1ubuntu1.7
libarchive13 –  3.6.0-1ubuntu1.7
20.04 LTS focal libarchive-dev –  3.4.0-2ubuntu1.5+esm2  
libarchive-tools –  3.4.0-2ubuntu1.5+esm2  
libarchive13 –  3.4.0-2ubuntu1.5+esm2  
18.04 LTS bionic bsdcpio –  3.2.2-3.1ubuntu0.7+esm3  
bsdtar –  3.2.2-3.1ubuntu0.7+esm3  
libarchive-dev –  3.2.2-3.1ubuntu0.7+esm3  
libarchive-tools –  3.2.2-3.1ubuntu0.7+esm3  
libarchive13 –  3.2.2-3.1ubuntu0.7+esm3  
16.04 LTS xenial bsdcpio –  3.1.2-11ubuntu0.16.04.8+esm3  
bsdtar –  3.1.2-11ubuntu0.16.04.8+esm3  
libarchive-dev –  3.1.2-11ubuntu0.16.04.8+esm3  
libarchive13 –  3.1.2-11ubuntu0.16.04.8+esm3  
14.04 LTS trusty bsdcpio –  3.1.2-7ubuntu2.8+esm5  
bsdtar –  3.1.2-7ubuntu2.8+esm5  
libarchive-dev –  3.1.2-7ubuntu2.8+esm5  
libarchive13 –  3.1.2-7ubuntu2.8+esm5  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›