VDB
GCVE-110-MAGEIA-2026-366
GCVE-110-MAGEIA-2026-366
Advisory Published
Double-free vulnerability in rar5 decompression logic via dangling
filtered_buf pointer in init_unpack(). (CVE-2026-14164)
Heap overflow oob read while parsing a tar archive contains a pax
extended header. (CVE-2026-15028)
A null pointer dereference vulnerability exists in the acl parser of
libarchive. (CVE-2026-5745)
Reading past eof may be triggered for piped file streams.
(CVE-2025-5918)
An issue was discovered in libarchive bsdtar before version 3.8.1 in
function apply_substitution in file tar/subst.c when processing crafted
-s substitution rules. This can cause unbounded memory allocation and
lead to denial of service (Out-of-Memory crash). (CVE-2025-60753)
Infinite loop denial of service in rar5 decompression via
archive_read_data() in libarchive. (CVE-2026-4111)
Information disclosure via heap out-of-bounds read in rar archive
processing. (CVE-2026-4424)
Denial of service via malformed iso file processing. (CVE-2026-4426)
Arbitrary code execution via integer overflow in iso9660 image
processing. (CVE-2026-5121)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | libarchive | 0 (affected), 3.8.9-1.mga10 (unaffected) | — |
| Mageia | libarchive | 0 (affected), 3.6.2-5.6.mga9 (unaffected) | — |
Browse GCVE Records
3,528 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.