[CLSA-2026:1777307149] libarchive: Fix of CVE-2021-31566
Type:
security
Severity:
Critical
Release date:
2026-04-27 16:25:54 UTC
Description:
- CVE-2021-31566: extend backport with upstream 8a1bd5c and ede459d2 to close the trailing-slash variant of the fixup-list symlink-follow attack
Updated packages:
  • bsdcpio-3.1.2-14.el7_7.tuxcare.els5.x86_64.rpm
    sha:2fe9e0030eaf602790ebdcd3b3e81451e25450c6a7ec72297ec5f0b2f2849371
  • bsdtar-3.1.2-14.el7_7.tuxcare.els5.x86_64.rpm
    sha:cd7ca2b9234ab2d6de780765fa7a85a985eeeb731ebd204a0834ca8fc3325ce3
  • libarchive-3.1.2-14.el7_7.tuxcare.els5.i686.rpm
    sha:56de1abcb649cf5734fdb3ea365620de597768fee1979f9814e3bf67adb86a97
  • libarchive-3.1.2-14.el7_7.tuxcare.els5.x86_64.rpm
    sha:3486e6942ccc74364217f93c20d49ad8d39292b5927db00da3ea6dcb232176aa
  • libarchive-devel-3.1.2-14.el7_7.tuxcare.els5.i686.rpm
    sha:e6ea6191f5828fde8458e6f9bcaf3d4ab612865535f7859a26d58c233c2c8235
  • libarchive-devel-3.1.2-14.el7_7.tuxcare.els5.x86_64.rpm
    sha:6c4726522133a3a2c1561fdfe76f806717ea328d2948486ed27c6ae65a9cd3f9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.