Your message dated Sat, 01 Aug 2026 03:04:32 +0000
with message-id <[email protected]>
and subject line Bug#1142834: fixed in libarchive 3.8.9-1
has caused the Debian Bug report #1142834,
regarding libarchive: CVE-2026-16517
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1142834: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142834
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libarchive
Version: 3.8.8-2
Severity: important
Tags: security upstream
Forwarded: https://github.com/libarchive/libarchive/issues/3225
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for libarchive.
CVE-2026-16517[0]:
| A signed integer overflow vulnerability was found in libarchive's
| ZIP writer. In the archive_write_zip_header function in
| archive_write_set_format_zip.c, when ZIP encryption is enabled and
| the entry file size is close to INT64_MAX, the addition of the
| encryption overhead to the entry size overflows int64_t, resulting
| in undefined behavior. This could lead to incorrect Zip64 extension
| decisions or potential memory corruption.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-16517
https://www.cve.org/CVERecord?id=CVE-2026-16517
[1] https://github.com/libarchive/libarchive/issues/3225
[2] https://github.com/libarchive/libarchive/pull/3228
[3]
https://github.com/libarchive/libarchive/commit/1c6e7b491f60fce335c20a9692f870d1f1ca39aa
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: libarchive
Source-Version: 3.8.9-1
Done: Syed Shahrukh Hussain <[email protected]>
We believe that the bug you reported is fixed in the latest version of
libarchive, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Syed Shahrukh Hussain <[email protected]> (supplier of updated
libarchive package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 1 Aug 2026 06:15:11 +0500
Source: libarchive
Architecture: source
Version: 3.8.9-1
Distribution: unstable
Urgency: medium
Maintainer: Gabriel Barrantes <[email protected]>
Changed-By: Syed Shahrukh Hussain <[email protected]>
Closes: 1142833 1142834
Changes:
libarchive (3.8.9-1) unstable; urgency=medium
.
* New upstream release.
- Fix CVE-2026-15028 (Closes: #1142833).
- Fix CVE-2026-16517 (Closes: #1142834).
Checksums-Sha1:
569d405236064d20c7ffc2352d3ace13198836c7 2658 libarchive_3.8.9-1.dsc
44c905f00d56fa650486ed3e19e4495afa1b0901 6617696 libarchive_3.8.9.orig.tar.xz
a6d80bc9bded1857baa6d90b8afe1372ee0f8c99 833 libarchive_3.8.9.orig.tar.xz.asc
5e98061b018a26fe612e41319f8e0438980f06bc 25176 libarchive_3.8.9-1.debian.tar.xz
c73c6adca5f865414e39d5f97e096fe78fb2c661 7613
libarchive_3.8.9-1_amd64.buildinfo
Checksums-Sha256:
ca2bdd0d703b82ec98f2ce92149bee2ecc81bf4b4e1c91e060c29c98ba2cd5e2 2658
libarchive_3.8.9-1.dsc
888c934f9d95648ecb9163dc8e23ab80a476ecb81a8f1154704a227b5b676dde 6617696
libarchive_3.8.9.orig.tar.xz
0d68cec14791e3733a51fbdb064f1bbb02c215aac5fc202128b5844c3461c1fe 833
libarchive_3.8.9.orig.tar.xz.asc
5980d11d348cb1872018e9d1891d047e137ad6d1ef8f96403b73c7ad479ee1d4 25176
libarchive_3.8.9-1.debian.tar.xz
223d32dad25d4076b4947543e67687f18d210cb436dccf00f3bb0fba42218e0a 7613
libarchive_3.8.9-1_amd64.buildinfo
Files:
1e4bf4d8512f0475cba641ee103d2c16 2658 libs optional libarchive_3.8.9-1.dsc
535e3afec5f61d493f0b1b9e8bcf7539 6617696 libs optional
libarchive_3.8.9.orig.tar.xz
ca71bcde5d794910bf7159527b460c28 833 libs optional
libarchive_3.8.9.orig.tar.xz.asc
ac65674919191baf475b12f172a03586 25176 libs optional
libarchive_3.8.9-1.debian.tar.xz
f12f819354f290ff153d29cc4634ad81 7613 libs optional
libarchive_3.8.9-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEljcSQ3PBMBm+EUvM62KxBX3nqLEFAmptXpMACgkQ62KxBX3n
qLG0fRAAlKOyqTS32AVqoINmKDzJ4199/IQZM6AJGkeDZKXPYDX8LdrXGCR6WVdY
3lmAK/61tBjE8JQQjKkiuqCswBtRCsFXAqEMzOPSMXAVsW3IoFrb4d3J2Oo+DQAU
Tel4FXKcI+DaRWqEi5TH4/NYFQfnF/YnvmN5KMTnhQ/SOEYZ3l3zx+vXnsEJkoQd
sJMSb2Xo47LbrZSb3rH5jBxQDKCXsbRXyAFAqDa6e1F6L9c5XqDoMzVrrJtyn0SX
Lv2GWTTYCRA+Jy8SzYJmZLH8lJ0plIhXbbCqCup6stVgN+D86GnZanZOx/OQyN5E
V1qbiZfUojYMNedX5DFU3ECninzdhd7dMxMkQ4RmEzV24GIZbjj49x5y3pc7CrU/
7B2NwfDyBcehUJyuTR8EMhn+FhTladUBmAb7Tz0b8aSZamEOUkDy4w2vkWbob/kx
uJYde0POtF9gC8DSwjafix9oPsTshIf5hX18lCZHyQ99lW/TYsrGAPiXcCbbiBV5
c+HNKGwnMeW29htTsgOpYl05WbmhdvlF62VR/GCLPnvM6EVlcY+qwLW8tE0Ynmn5
betk2Eh3jjJxf39Zt3DDr5LJASBxuzF+UzxD+0fAfYfVoxMVB1n7ujkzjfBBUT8b
ibqvvmf4uwNFCyTE4Nx5f5ib+1fCnMej0NooMuEddGpgd+0hJHs=
=y5hG
-----END PGP SIGNATURE-----
pgpicaqQ2nGYk.pgp
Description: PGP signature
--- End Message ---