[CLSA-2026:1782303221] libarchive: Fix of CVE-2025-25724
Type:
security
Severity:
Important
Release date:
2026-06-24 12:13:57 UTC
Description:
- CVE-2026-4424: fix RAR LZSS window size mismatch after PPMd block (heap OOB read)
CVEs fixed:
Updated packages:
  • bsdcpio-3.1.2-14.el7_7.tuxcare.els8.x86_64.rpm
    sha:db4ee3aea4aa65f2843faf192c87123a754019db9f0387ba0f99ca92be34de57
  • bsdtar-3.1.2-14.el7_7.tuxcare.els8.x86_64.rpm
    sha:280c3f87eadb7e177081fc0cc06e6870f6e55bff39b7201362dd99845333128a
  • libarchive-3.1.2-14.el7_7.tuxcare.els8.i686.rpm
    sha:212e9353e94d8fda2050c27a9ace3de54d5b5ff6e557a4549e424d9b89ee49c1
  • libarchive-3.1.2-14.el7_7.tuxcare.els8.x86_64.rpm
    sha:952b846438823f6e1b60ae7db861ef4c572185912d7e6ed13dd9c847020cf336
  • libarchive-devel-3.1.2-14.el7_7.tuxcare.els8.i686.rpm
    sha:55f320084de5724311bbd54c5bf133f78e2c514f53698c9f73a3685068b7ff15
  • libarchive-devel-3.1.2-14.el7_7.tuxcare.els8.x86_64.rpm
    sha:8db630a87bb1685ded7f336fee29ec72aea22fe84c019acb0491f24b88dd7a85
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.