Skip to content
SUSE Libarchive Vulnerabilities Prompt Urgent Security Updates

SUSE Libarchive Vulnerabilities Prompt Urgent Security Updates

First seen 25 Jun 2026, 18:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 26, 2026 at 17:55 UTC
  • •SUSE released critical updates for libarchive addressing multiple vulnerabilities.
  • •Vulnerabilities include denial of service and arbitrary code execution risks.
  • •Users should apply patches immediately to mitigate potential threats.

SUSE has released important updates for libarchive addressing multiple vulnerabilities, including CVE-2025-60753, CVE-2026-4111, CVE-2026-4424, CVE-2026-4426, and CVE-2026-5121. These vulnerabilities include issues such as denial of service, arbitrary code execution, and information disclosure. Affected systems include various SUSE Linux distributions utilizing libarchive. The vulnerabilities were disclosed between March 2026 and November 2025, with critical CVSS scores indicating significant risk. Users are advised to apply the patches using SUSE's recommended installation methods. The updates were released on June 18 and June 22, 2026, with the most recent advisory published on June 25, 2026. The vulnerabilities could lead to severe operational disruptions if not addressed promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 97d ago How this analysis works

Timeline

2025-11-05
CVE-2025-60753 published
A vulnerability in bsdtar causing hangs and OOMs with zero-length pattern matches was disclosed.
Linuxsecurity
2026-03-13
CVE-2026-4111 published
A logical deadlock in the RAR5 filter subsystem leading to infinite loops and DoS was disclosed.
Linuxsecurity
2026-03-19
CVE-2026-4424 published
An information disclosure vulnerability via heap out-of-bounds read in RAR archive processing was disclosed.
Linuxsecurity
2026-03-19
CVE-2026-4426 published
Undefined behavior due to unvalidated operand in shift expression of zisofs decompression code was disclosed.
Linuxsecurity
2026-03-30
CVE-2026-5121 published
An arbitrary code execution vulnerability via integer overflow in ISO9660 image processing was disclosed.
Linuxsecurity
2026-06-18
SUSE releases updates for libarchive
SUSE released important updates addressing multiple vulnerabilities in libarchive.
Linuxsecurity
2026-06-22
Additional updates for libarchive released
SUSE issued further updates for libarchive to address critical vulnerabilities.
Linuxsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2025-60753 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed