RHSA-2026:56954: Moderate: libarchive security update
Moderate: libarchive security update
Other sources
The libarchive programming library can create and read several different streaming archive formats, including GNU tar, cpio, and ISO 9660 CD-ROM images. Libarchive is used notably in the bsdtar utility, scripting language bindings such as python-libarchive, and several popular desktop file managers.Security Fix(es): libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filteredbuf pointer in initunpack() (CVE-2026-14164) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libarchiveto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1 - Upgrade
Upgrade
redhat/bsdcat-debuginfoto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1 - Upgrade
Upgrade
redhat/bsdcpio-debuginfoto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1 - Upgrade
Upgrade
redhat/bsdtarto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1 - Upgrade
Upgrade
redhat/bsdtar-debuginfoto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1 - Upgrade
Upgrade
redhat/bsdunzip-debuginfoto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1 - Upgrade
Upgrade
redhat/libarchive-debuginfoto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1 - Upgrade
Upgrade
redhat/libarchive-debugsourceto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1 - Upgrade
Upgrade
redhat/libarchive-develto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1 - Upgrade
Upgrade
redhat/bsdcat-debuginfoto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1.aa - Upgrade
Upgrade
redhat/bsdcpio-debuginfoto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1.aa - Upgrade
Upgrade
redhat/bsdtarto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1.aa - Upgrade
Upgrade
redhat/bsdtar-debuginfoto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1.aa - Upgrade
Upgrade
redhat/bsdunzip-debuginfoto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1.aa - Upgrade
Upgrade
redhat/libarchiveto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1.aa - Upgrade
Upgrade
redhat/libarchive-debuginfoto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1.aa - Upgrade
Upgrade
redhat/libarchive-debugsourceto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1.aa - Upgrade
Upgrade
redhat/libarchive-develto a version that resolves this vulnerability.Fixed in 3.7.7-5.el10_0.1.aa
Event History
Frequently Asked Questions
What input would need to be processed to trigger this issue?
The issue is in libarchive's RAR5 decompression logic. An attacker would need to cause an affected application to process a crafted RAR5 archive.
Which applications may be exposed through this library?
Exposure can include applications that use libarchive to read archives, notably bsdtar, python-libarchive bindings, and desktop file managers. The advisory also lists the bsdtar package among affected software.
How can I determine whether my system needs this update?
Check whether the listed Red Hat libarchive or bsdtar packages are installed and whether the RHSA-2026:56954 security update has been applied. Debug and debuginfo packages are also listed in the advisory.