CVE-2026-15028

EUVD-2026-42865
A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.9 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 20.49%
Debian logo
Debian Releases
Debian Product
Codename
libarchive
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
3.8.9-1
fixed
sid
3.8.9-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libarchive
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
resolute
Fixed 3.8.5-1ubuntu2.2
released
trusty
not-affected
xenial
not-affected
Azure Linux logo
Azure Linux Releases
Azure Package
Release
libarchive
Azure Linux 3.0
0:3.7.7-7.azl3
fixed