Bugzilla – Bug 1197634
VUL-0: CVE-2022-26280: libarchive: out-of-bounds read via the component zipx_lzma_alone_init
Last modified: 2022-09-29 12:35:55 UTC
CVE-2022-26280 Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init. Upstream fix commit: https://github.com/libarchive/libarchive/commit/cfaa28168a07ea4a53276b63068f94fce37d6aff References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-26280 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26280 https://github.com/libarchive/libarchive/issues/1672 http://www.cvedetails.com/cve/CVE-2022-26280/
I think the bug was introduced in v3.4.0 with this commit [0]. Only the following are affected: - SUSE:SLE-15-SP2:Update - SUSE:SLE-15-SP4:Update - openSUSE:Factory [0] https://github.com/libarchive/libarchive/commit/121035c83e18b70d3128e9ac966109ebedb7e516
The rating of this bug has been reevaluated and became LTSS worthy. Danilo, could you please submit to SUSE:SLE-15-SP2:Update and SUSE:SLE-15-SP4:Update? :)
(In reply to Thomas Leroy from comment #2) > The rating of this bug has been reevaluated and became LTSS worthy. > Danilo, could you please submit to SUSE:SLE-15-SP2:Update and > SUSE:SLE-15-SP4:Update? :) Sure, I have just submitted the fix :)
SUSE-SU-2022:1803-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1197634 CVE References: CVE-2022-26280 JIRA References: Sources used: openSUSE Leap 15.3 (src): libarchive-3.4.2-150200.4.6.1 SUSE Linux Enterprise Module for Development Tools 15-SP3 (src): libarchive-3.4.2-150200.4.6.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): libarchive-3.4.2-150200.4.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:1930-1: An update that solves three vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 1022528,1188572,1189528,1197634 CVE References: CVE-2017-5601,CVE-2021-36976,CVE-2022-26280 JIRA References: Sources used: openSUSE Leap 15.4 (src): libarchive-3.5.1-150400.3.3.1 SUSE Linux Enterprise Module for Development Tools 15-SP4 (src): libarchive-3.5.1-150400.3.3.1 SUSE Linux Enterprise Module for Basesystem 15-SP4 (src): libarchive-3.5.1-150400.3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
*** Bug 1199230 has been marked as a duplicate of this bug. ***
Done, closing.