USN-7070-1: libarchive vulnerabilities
It was discovered that libarchive mishandled certain memory checks, which could result in a NULL pointer dereference. An attacker could potentially use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-36227) It was discovered that libarchive mishandled certain memory operations, which could result in an out-of-bounds memory access. An attacker could potentially use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-48957, CVE-2024-48958)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7070-1?
USN-7070-1 has been identified as a denial of service vulnerability due to NULL pointer dereference in libarchive.
How do I fix USN-7070-1?
To fix USN-7070-1, update libarchive to the latest patched version for your Ubuntu release.
Which versions of Ubuntu are affected by USN-7070-1?
USN-7070-1 affects Ubuntu 14.04 LTS, 16.04 LTS, 18.04 LTS, 20.04 LTS, and 22.04 LTS.
What can an attacker do with USN-7070-1?
An attacker could exploit USN-7070-1 to cause a denial of service, making the system unresponsive.
Is there a workaround for USN-7070-1?
There is no official workaround for USN-7070-1; the recommended action is to apply the security updates.