Skip to content

[Deepin Integration]~[v25-Release] fix(libarchive): CVE-2026-14164 by deepin-ci-robot@deepin-community/libarchive by deepin-community-ci-bot[bot] #13642

Description

@deepin-bot

Package information | 软件包信息

包名 版本
libarchive 3.7.4-4+deb13u1deepin2

Package repository address | 软件包仓库地址

deb [trusted=yes] https://ci.deepin.com/repo/obs/deepin:/CI:/TestingIntegration:/test-integration-pr-4235/testing/ ./

Changelog | 更新信息

libarchive (3.7.4-4+deb13u1deepin2) unstable; urgency=medium

  • Fix CVE-2026-14164: Double free in libarchive RAR5 reader.
    Clear filtered_buf and window_buf pointers to NULL after freeing
    in init_unpack, preventing access through dangling pointers.
    Upstream: libarchive/libarchive@1c914cd

Metadata

Metadata

Assignees

Type

No type

Projects

Status
已集成

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions