[Git][security-tracker-team/security-tracker][master] Track fixed version for two libarchive issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 1 06:35:41 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6c34035c by Salvatore Bonaccorso at 2026-08-01T07:35:10+02:00
Track fixed version for two libarchive issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -10537,11 +10537,12 @@ CVE-2026-21954 (Vulnerability in the Oracle Retail Xstore Point of Service produ
 CVE-2026-21953 (Vulnerability in the Oracle Retail Xstore Point of Service product of  ...)
 	NOT-FOR-US: Oracle
 CVE-2026-16517 (A signed integer overflow vulnerability was found in libarchive's ZIP  ...)
-	- libarchive <unfixed> (bug #1142834)
+	- libarchive 3.8.9-1 (bug #1142834)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2505492
 	NOTE: https://github.com/libarchive/libarchive/issues/3225
 	NOTE: https://github.com/libarchive/libarchive/pull/3228
 	NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/1c6e7b491f60fce335c20a9692f870d1f1ca39aa
+	NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/4bb52f4934113059cfa23a2375f3bad9f124ff90 (v3.8.9)
 CVE-2026-16492 (A weakness has been identified in umijs umi up to 4.6.63. The affected ...)
 	NOT-FOR-US: umijs umi
 CVE-2026-16490 (A security flaw has been discovered in itsourcecode Hospital Managemen ...)
@@ -20639,10 +20640,11 @@ CVE-2026-15143 (A flaw was found in the file_type content detector of guardrails
 CVE-2026-15104 (The BetterDocs \u2013 AI Documentation, Knowledge Base, Docs, Wikis, F ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15028 (A flaw was found in libarchive. This vulnerability allows a remote att ...)
-	- libarchive <unfixed> (bug #1142833)
+	- libarchive 3.8.9-1 (bug #1142833)
 	NOTE: https://github.com/libarchive/libarchive/issues/3251
 	NOTE: https://github.com/libarchive/libarchive/pull/3253
-	NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/c16162083a247efd4a2bc71401489bec3090ae7c
+	NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/f93abd161ec37326c566f4f0efcd44fe7a66dd95
+	NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/ffc1114f84953b9b9c79a36798e534d07194e85b (v3.8.9)
 CVE-2026-15026 (The Import and export users and customers plugin for WordPress is vuln ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14475 (The Cookie Banner for GDPR / CCPA \u2013 WPLP Cookie Consent plugin fo ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c34035c2c1fabc3b2cd198de2c6952b8fcb5856

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c34035c2c1fabc3b2cd198de2c6952b8fcb5856
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/0512f25f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list