Back Linuxsecurity SUSE libarchive Moderate Denial of Service Fix Vuln 2026-23062
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
## This update for libarchive fixes the following issues: * creating temporary files in the current working directory instead of the target directory can lead to file creation failures when the working directory is not writable (bsc#1254340). * file descriptor leak in the mtree parser cleanup path could lead to file descriptor exhaustion and denial of service (bsc#1261003). * NULL pointer dereference in archive_acl_from_text_w() could lead to a segmentation fault (bsc#1260998). * reading from an invalid index when buffer size is smaller than H_LEVEL_OFFSET can lead to an out-of-bounds buffer overrun (bsc#1254341). * incorrect pointer handling for RAR5 files declaring over 8192 filters can lead to excessive resource usage and denial of service (bsc#1261002) ## Patch Instructions:
## This update for libarchive fixes the following issues: * creating temporary files in the current working directory instead of the target directory can lead to file creation failures when the working directory is not writable (bsc#1254340). * file descriptor leak in the mtree parser cleanup path could lead to file descriptor exhaustion and denial of service (bsc#1261003). * NULL pointer dereference in archive_acl_from_text_w() could lead to a segmentation fault (bsc#1260998). * reading from an invalid index when buffer size is smaller than H_LEVEL_OFFSET can lead to an out-of-bounds buffer overrun (bsc#1254341). * incorrect pointer handling for RAR5 files declaring over 8192 filters can lead to excessive resource usage and denial of service (bsc#1261002) ## Patch Instructions:
* SUSE Linux Micro 6.0
An update that has five fixes can now be installed.
*
*
*
*
*
Announcement ID: SUSE-SU-2026:23062-1 Release Date: 2026-08-10T10:53:11Z Rating: moderate
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
