Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:8492 - Security Advisory
Issued:
2026-04-16
Updated:
2026-04-16

RHSA-2026:8492 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libarchive security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libarchive is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libarchive programming library can create and read several different streaming archive formats, including GNU tar, cpio, and ISO 9660 CD-ROM images. Libarchive is used notably in the bsdtar utility, scripting language bindings such as python-libarchive, and several popular desktop file managers.

Security Fix(es):

  • libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing (CVE-2026-4424)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64

Fixes

  • BZ - 2449006 - CVE-2026-4424 libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing

CVEs

  • CVE-2026-4424

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
libarchive-3.7.7-8.el10_1.src.rpm SHA-256: 0f24716615f3fc6a5e425d1e66e7ba86ef0a97b4e6b8ed86825664180d29fd4d
x86_64
bsdcat-debuginfo-3.7.7-8.el10_1.x86_64.rpm SHA-256: 2fa0646ce126e62190dbf3aaedc0b1118541d2d12f6c5c755ab55b8631b93241
bsdcat-debuginfo-3.7.7-8.el10_1.x86_64.rpm SHA-256: 2fa0646ce126e62190dbf3aaedc0b1118541d2d12f6c5c755ab55b8631b93241
bsdcpio-debuginfo-3.7.7-8.el10_1.x86_64.rpm SHA-256: 3c970db22449d9399a295c436ec7aee81d0c2ab115825f9b3d41a99210f89ed5
bsdcpio-debuginfo-3.7.7-8.el10_1.x86_64.rpm SHA-256: 3c970db22449d9399a295c436ec7aee81d0c2ab115825f9b3d41a99210f89ed5
bsdtar-3.7.7-8.el10_1.x86_64.rpm SHA-256: 11d85a8e55a5f265990f4b2f925616245ef82b17f2565fa0db72b976d6d676e9
bsdtar-debuginfo-3.7.7-8.el10_1.x86_64.rpm SHA-256: f2109de91e0a75322dcfa099f5b3dfdb2521551624845e07c05cb51d18e4b488
bsdtar-debuginfo-3.7.7-8.el10_1.x86_64.rpm SHA-256: f2109de91e0a75322dcfa099f5b3dfdb2521551624845e07c05cb51d18e4b488
bsdunzip-debuginfo-3.7.7-8.el10_1.x86_64.rpm SHA-256: 9b850bea2b636bb7e1c22b3991e5728429c8fbe63758b129db0f76065070b1e8
bsdunzip-debuginfo-3.7.7-8.el10_1.x86_64.rpm SHA-256: 9b850bea2b636bb7e1c22b3991e5728429c8fbe63758b129db0f76065070b1e8
libarchive-3.7.7-8.el10_1.x86_64.rpm SHA-256: 3f768e67ee5a8a40341713c367501abbdf9611f570322ad94efc54216b80c3cd
libarchive-debuginfo-3.7.7-8.el10_1.x86_64.rpm SHA-256: eae36cdc9da5ffbd042efd1034fc793d7ce8764cbd3ee0e9b881fd347b66cab1
libarchive-debuginfo-3.7.7-8.el10_1.x86_64.rpm SHA-256: eae36cdc9da5ffbd042efd1034fc793d7ce8764cbd3ee0e9b881fd347b66cab1
libarchive-debugsource-3.7.7-8.el10_1.x86_64.rpm SHA-256: 677779e369cf43be91d4c9c5fd4d16d79e4510b52614b2f430c1a9789a8b9efd
libarchive-debugsource-3.7.7-8.el10_1.x86_64.rpm SHA-256: 677779e369cf43be91d4c9c5fd4d16d79e4510b52614b2f430c1a9789a8b9efd
libarchive-devel-3.7.7-8.el10_1.x86_64.rpm SHA-256: f5f8d8023a4928c02ed7a707028426ec0bb592e0e77e504279d422da27276cc8

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
libarchive-3.7.7-8.el10_1.src.rpm SHA-256: 0f24716615f3fc6a5e425d1e66e7ba86ef0a97b4e6b8ed86825664180d29fd4d
s390x
bsdcat-debuginfo-3.7.7-8.el10_1.s390x.rpm SHA-256: 7f76b1424af17ce82ea97b8887b9a4d35b1ad440382765b1aa992730c51ea373
bsdcat-debuginfo-3.7.7-8.el10_1.s390x.rpm SHA-256: 7f76b1424af17ce82ea97b8887b9a4d35b1ad440382765b1aa992730c51ea373
bsdcpio-debuginfo-3.7.7-8.el10_1.s390x.rpm SHA-256: fa722e6e4de48492149ac5f273db738c4d75a26ad0bbdda1d53265132f5e48f0
bsdcpio-debuginfo-3.7.7-8.el10_1.s390x.rpm SHA-256: fa722e6e4de48492149ac5f273db738c4d75a26ad0bbdda1d53265132f5e48f0
bsdtar-3.7.7-8.el10_1.s390x.rpm SHA-256: ffc4353ec927b8ac257bfa4ecc2e1a73e33b18e29db896661c50e89e83537402
bsdtar-debuginfo-3.7.7-8.el10_1.s390x.rpm SHA-256: 8b673586e044a12aba8b9a489c5d9229cd4ebda90be166921b81597706daf85e
bsdtar-debuginfo-3.7.7-8.el10_1.s390x.rpm SHA-256: 8b673586e044a12aba8b9a489c5d9229cd4ebda90be166921b81597706daf85e
bsdunzip-debuginfo-3.7.7-8.el10_1.s390x.rpm SHA-256: bdc92ef9739f53c6232ce8d3becabbea3017b87d918cf8fe3e0a0c5bdeda7a22
bsdunzip-debuginfo-3.7.7-8.el10_1.s390x.rpm SHA-256: bdc92ef9739f53c6232ce8d3becabbea3017b87d918cf8fe3e0a0c5bdeda7a22
libarchive-3.7.7-8.el10_1.s390x.rpm SHA-256: e842791fa0f912e60c83c742a9c865c8bd8f13e47fd847813b85418818fc4abf
libarchive-debuginfo-3.7.7-8.el10_1.s390x.rpm SHA-256: 5cbbdd767d12298b69119583b0815d02e10768e6942bcbb4bd5caa3d1d6cd00f
libarchive-debuginfo-3.7.7-8.el10_1.s390x.rpm SHA-256: 5cbbdd767d12298b69119583b0815d02e10768e6942bcbb4bd5caa3d1d6cd00f
libarchive-debugsource-3.7.7-8.el10_1.s390x.rpm SHA-256: 3e7bb05375fbbf99b01f350a0902501cb89c74c6c2d97735acfe9634cea9c4ef
libarchive-debugsource-3.7.7-8.el10_1.s390x.rpm SHA-256: 3e7bb05375fbbf99b01f350a0902501cb89c74c6c2d97735acfe9634cea9c4ef
libarchive-devel-3.7.7-8.el10_1.s390x.rpm SHA-256: da2d8194c20d3234797f8eb1a19ae6bcbe77485f8d13982d59f202091a868a6f

Red Hat Enterprise Linux for Power, little endian 10

SRPM
libarchive-3.7.7-8.el10_1.src.rpm SHA-256: 0f24716615f3fc6a5e425d1e66e7ba86ef0a97b4e6b8ed86825664180d29fd4d
ppc64le
bsdcat-debuginfo-3.7.7-8.el10_1.ppc64le.rpm SHA-256: 35c152f0aed036714dffee4a9efbf15056db13d28f0bb4774d0eca68c2a47a0a
bsdcat-debuginfo-3.7.7-8.el10_1.ppc64le.rpm SHA-256: 35c152f0aed036714dffee4a9efbf15056db13d28f0bb4774d0eca68c2a47a0a
bsdcpio-debuginfo-3.7.7-8.el10_1.ppc64le.rpm SHA-256: cae3a898020f241b4c7cd4cedc23ba70d193a83d64e53532f3d933b923516e2e
bsdcpio-debuginfo-3.7.7-8.el10_1.ppc64le.rpm SHA-256: cae3a898020f241b4c7cd4cedc23ba70d193a83d64e53532f3d933b923516e2e
bsdtar-3.7.7-8.el10_1.ppc64le.rpm SHA-256: e230e1cba4b7fdba9d4e2da079e39d98160ee8df14919b292f7b5be8cf31c874
bsdtar-debuginfo-3.7.7-8.el10_1.ppc64le.rpm SHA-256: 2a97c10d7bbdd968fa175c341f1002acf1ccb7558d2a518b0721f8a2556055e6
bsdtar-debuginfo-3.7.7-8.el10_1.ppc64le.rpm SHA-256: 2a97c10d7bbdd968fa175c341f1002acf1ccb7558d2a518b0721f8a2556055e6
bsdunzip-debuginfo-3.7.7-8.el10_1.ppc64le.rpm SHA-256: 78462b1299b25e55d32b9aad2d71339fabe9e1b8f76d3fe64f8293e135580062
bsdunzip-debuginfo-3.7.7-8.el10_1.ppc64le.rpm SHA-256: 78462b1299b25e55d32b9aad2d71339fabe9e1b8f76d3fe64f8293e135580062
libarchive-3.7.7-8.el10_1.ppc64le.rpm SHA-256: fe3c71ee835672d77f97c361d7f6709cf31f37a2ff771810232437f7c54b8d48
libarchive-debuginfo-3.7.7-8.el10_1.ppc64le.rpm SHA-256: ad1fa972a829c9101fc570507fc823395669b6bbd59c6e8155cc2c41b85fb5d1
libarchive-debuginfo-3.7.7-8.el10_1.ppc64le.rpm SHA-256: ad1fa972a829c9101fc570507fc823395669b6bbd59c6e8155cc2c41b85fb5d1
libarchive-debugsource-3.7.7-8.el10_1.ppc64le.rpm SHA-256: 94d5eb50f1d8c8ee64ecc89cfb38e9436e746a1a6bd0716d8e3c73088e859938
libarchive-debugsource-3.7.7-8.el10_1.ppc64le.rpm SHA-256: 94d5eb50f1d8c8ee64ecc89cfb38e9436e746a1a6bd0716d8e3c73088e859938
libarchive-devel-3.7.7-8.el10_1.ppc64le.rpm SHA-256: f842c4d10889252072ae06a889edb95138c71b3a8122f69320ad8c389fdf050c

Red Hat Enterprise Linux for ARM 64 10

SRPM
libarchive-3.7.7-8.el10_1.src.rpm SHA-256: 0f24716615f3fc6a5e425d1e66e7ba86ef0a97b4e6b8ed86825664180d29fd4d
aarch64
bsdcat-debuginfo-3.7.7-8.el10_1.aarch64.rpm SHA-256: 15321fcbdf7370e3ed11ed9d8f2f10300fbd307a51dd596f7282e3b73a3d8766
bsdcat-debuginfo-3.7.7-8.el10_1.aarch64.rpm SHA-256: 15321fcbdf7370e3ed11ed9d8f2f10300fbd307a51dd596f7282e3b73a3d8766
bsdcpio-debuginfo-3.7.7-8.el10_1.aarch64.rpm SHA-256: dabdbfdb628ec670593d7e8d02c55d48eff11d476dd0aadbc2c0a37eb3e9b63f
bsdcpio-debuginfo-3.7.7-8.el10_1.aarch64.rpm SHA-256: dabdbfdb628ec670593d7e8d02c55d48eff11d476dd0aadbc2c0a37eb3e9b63f
bsdtar-3.7.7-8.el10_1.aarch64.rpm SHA-256: d88436b5fc9efe955993518156d7d889f9c6e25b379cebba115754e1ee9e1c51
bsdtar-debuginfo-3.7.7-8.el10_1.aarch64.rpm SHA-256: 802e74582920ed8e8cc0419e097182f7b839ae1c7f159bc6c5108a9d92bb426b
bsdtar-debuginfo-3.7.7-8.el10_1.aarch64.rpm SHA-256: 802e74582920ed8e8cc0419e097182f7b839ae1c7f159bc6c5108a9d92bb426b
bsdunzip-debuginfo-3.7.7-8.el10_1.aarch64.rpm SHA-256: 4182272ee7fc3072d421279ac195234d8239dea01648f91b32b81b08b6ce6293
bsdunzip-debuginfo-3.7.7-8.el10_1.aarch64.rpm SHA-256: 4182272ee7fc3072d421279ac195234d8239dea01648f91b32b81b08b6ce6293
libarchive-3.7.7-8.el10_1.aarch64.rpm SHA-256: 7eccd4aeb542937443c38d1df552c06e99140a9c2b76c1bc8a4ca6f73d58ce6d
libarchive-debuginfo-3.7.7-8.el10_1.aarch64.rpm SHA-256: 4dc989b2e21466b6cdbb5f626e04ed80985c6e979d4d5dfacaec827dcedc342c
libarchive-debuginfo-3.7.7-8.el10_1.aarch64.rpm SHA-256: 4dc989b2e21466b6cdbb5f626e04ed80985c6e979d4d5dfacaec827dcedc342c
libarchive-debugsource-3.7.7-8.el10_1.aarch64.rpm SHA-256: 6a58ec6309f52c3674ded9c4616ed12a1213f2b4f0ca5c745525cfd3444d71b3
libarchive-debugsource-3.7.7-8.el10_1.aarch64.rpm SHA-256: 6a58ec6309f52c3674ded9c4616ed12a1213f2b4f0ca5c745525cfd3444d71b3
libarchive-devel-3.7.7-8.el10_1.aarch64.rpm SHA-256: 84eb3c25a4c1d8a283319b19e3f5c1eda0afa3316bebee285e94e54dc9e05c8b

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility