CVE-2022-26280: Medium severity oracle libarchive vulnerability
Published Mar 28, 2022
·Updated
Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipxlzmaaloneinit.
Affected Software
2 affected components
Libarchive libarchive=3.6.0
Fedoraproject Fedora=36
Event History
Mar 28, 2022
CVE Published
via MITRE·09:28 PM
Data Sourced
via MITRE·09:28 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-26280?
CVE-2022-26280 is a vulnerability discovered in Libarchive v3.6.0 that allows an out-of-bounds read via the component zipx_lzma_alone_init.
2
What is the severity of CVE-2022-26280?
CVE-2022-26280 has a severity rating of 6.5 (medium).
3
How does CVE-2022-26280 affect Libarchive?
CVE-2022-26280 affects Libarchive v3.6.0.
4
How can I fix CVE-2022-26280?
To fix CVE-2022-26280, it is recommended to update Libarchive to a version that is not affected.
5
Where can I find more information about CVE-2022-26280?
More information about CVE-2022-26280 can be found in the references provided: [1] [2] [3].