[Git][security-tracker-team/security-tracker][master] Reserve DLA-4762-1 for libarchive

Abhijith PA (@abhijith) abhijith at debian.org
Mon Aug 31 08:19:10 BST 2026



Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker


Commits:
07f44ef0 by Abhijith PA at 2026-08-31T12:48:49+05:30
Reserve DLA-4762-1 for libarchive

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -64577,8 +64577,6 @@ CVE-2026-28979 (An out-of-bounds access issue was addressed with improved bounds
 CVE-2026-14164 (A double free issue has been identified in libarchive's RAR5 reader. D ...)
 	- libarchive 3.8.8-1 (bug #1141180)
 	[trixie] - libarchive <no-dsa> (Minor issue)
-	[bookworm] - libarchive <postponed> (Minor issue, DoS)
-	[bullseye] - libarchive <postponed> (Minor issue, DoS)
 	NOTE: https://github.com/libarchive/libarchive/issues/3069
 	NOTE: https://github.com/libarchive/libarchive/pull/3071
 	NOTE: https://github.com/libarchive/libarchive/commit/1c914cdfef533cbee1ae3aa21a89ba02ed4d5f61 (master)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,7 @@
+[31 Aug 2026] DLA-4762-1 libarchive - security update
+	{CVE-2026-14164 CVE-2026-15028 CVE-2026-16517}
+	[bullseye] - libarchive 3.4.3-2+deb11u5
+	[bookworm] - libarchive 3.6.2-1+deb12u5
 [30 Aug 2026] DLA-4761-1 libnet-dns-perl - security update
 	{CVE-2026-64194}
 	[bullseye] - libnet-dns-perl 1.29-1+deb11u1


=====================================
data/dla-needed.txt
=====================================
@@ -321,9 +321,6 @@ ldap-account-manager
 libapache2-mod-auth-openidc (dleidert)
   NOTE: 20260830: Added by Front-Desk (dleidert)
 --
-libarchive (Abhijith PA)
-  NOTE: 20260804: Added by Front-Desk. Take care of CVE-2026-15028 (rouca)
---
 libass
   NOTE: 20260712: Added by Front-Desk (utkarsh)
   NOTE: 20260712: TEMP-0000000-AA08BC (GHSA-pjjp-65r7-ppgm): OOB read+write in wrap_lines_measure from untrusted subtitles; secteam fixed stable via point release. Affected in bullseye (0.15.0) and bookworm (0.17.1). (utkarsh/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07f44ef04ebede918f9663feef408b054f02e9b2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07f44ef04ebede918f9663feef408b054f02e9b2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/e0774b8f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list