First published: Mon Mar 28 2022(Updated: )
Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libarchive Libarchive | =3.6.0 | |
Fedoraproject Fedora | =36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26280 is a vulnerability discovered in Libarchive v3.6.0 that allows an out-of-bounds read via the component zipx_lzma_alone_init.
CVE-2022-26280 has a severity rating of 6.5 (medium).
CVE-2022-26280 affects Libarchive v3.6.0.
To fix CVE-2022-26280, it is recommended to update Libarchive to a version that is not affected.
More information about CVE-2022-26280 can be found in the references provided: [1] [2] [3].