Home / mailings [USN-8902-1] libarchive vulnerability
Posted on 08 October 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8902-1
October 08, 2026
libarchive vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
libarchive could be made to crash or run programs as your login if it
opened a specially crafted file.
Software Description:
- libarchive: Library to read/write archive files
Details:
It was discovered that libarchive had a signed integer overflow in its
ZIP writer when handling encrypted entries with sizes near the maximum
value. An attacker could possibly use this issue to cause libarchive to
crash or execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
libarchive13t64 3.8.5-1ubuntu2.3
Ubuntu 24.04 LTS
libarchive13t64 3.7.2-2ubuntu0.9
Ubuntu 22.04 LTS
libarchive13 3.6.0-1ubuntu1.9
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8902-1
CVE-2026-16517
Package Information:
https://launchpad.net/ubuntu/+source/libarchive/3.8.5-1ubuntu2.3
https://launchpad.net/ubuntu/+source/libarchive/3.7.2-2ubuntu0.9
https://launchpad.net/ubuntu/+source/libarchive/3.6.0-1ubuntu1.9
--===============4747164534538185354==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
