[CLSA-2026:1777544831] libarchive: Fix of CVE-2021-31566
Type:
security
Severity:
Critical
Release date:
2026-05-02 01:13:19 UTC
Description:
- CVE-2021-31566: extend backport with upstream 8a1bd5c and ede459d2 to close the trailing-slash variant of the fixup-list symlink-follow attack
Updated packages:
  • bsdcpio-3.1.2-14.el7_7.tuxcare.els5.x86_64.rpm
    sha:f01dcf48070e0b0df3578752fc687e8e6108f1e4bd3974094b1f7e4be09a20b0
  • bsdtar-3.1.2-14.el7_7.tuxcare.els5.x86_64.rpm
    sha:7d72074e23ce677c0e44916e017334df2b82461ccee4120d9b385681f8f4b7c4
  • libarchive-3.1.2-14.el7_7.tuxcare.els5.i686.rpm
    sha:87026c5fbcd20695d5af20443a419673f987a517d4ca5e6ab60469d09de3507f
  • libarchive-3.1.2-14.el7_7.tuxcare.els5.x86_64.rpm
    sha:cf772fcc047031719c9df5ac0240942dd988087c01da84e07b34d38c43b15e90
  • libarchive-devel-3.1.2-14.el7_7.tuxcare.els5.i686.rpm
    sha:2acc346cfea6eae073cde3c9bb7925e1abd8d94c0fcc23a056c15d5eaf183981
  • libarchive-devel-3.1.2-14.el7_7.tuxcare.els5.x86_64.rpm
    sha:d65d369162e7e6e9744ecb05775a3eac9ca59717f9c371e57aab6b1949147ec3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.