CVE-2026-16517

NameCVE-2026-16517
DescriptionA signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1142834

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libarchive (PTS)bullseye3.4.3-2+deb11u1vulnerable
bullseye (security)3.4.3-2+deb11u4vulnerable
bookworm3.6.2-1+deb12u4vulnerable
bookworm (security)3.6.2-1+deb12u2vulnerable
trixie3.7.4-4+deb13u1vulnerable
forky, sid3.8.9-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libarchivesource(unstable)3.8.9-11142834

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2505492
https://github.com/libarchive/libarchive/issues/3225
https://github.com/libarchive/libarchive/pull/3228
Fixed by: https://github.com/libarchive/libarchive/commit/1c6e7b491f60fce335c20a9692f870d1f1ca39aa
Fixed by: https://github.com/libarchive/libarchive/commit/4bb52f4934113059cfa23a2375f3bad9f124ff90 (v3.8.9)

Search for package or bug name: Reporting problems