Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:8517 - Security Advisory
Issued:
2026-04-16
Updated:
2026-04-16

RHSA-2026:8517 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libarchive security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libarchive is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libarchive programming library can create and read several different streaming archive formats, including GNU tar, cpio, and ISO 9660 CD-ROM images. Libarchive is used notably in the bsdtar utility, scripting language bindings such as python-libarchive, and several popular desktop file managers.

Security Fix(es):

  • libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing (CVE-2026-4424)
  • libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing (CVE-2026-5121)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2449006 - CVE-2026-4424 libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing
  • BZ - 2452945 - CVE-2026-5121 libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing

CVEs

  • CVE-2026-4424
  • CVE-2026-5121

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
libarchive-3.1.2-14.el7_9.2.src.rpm SHA-256: 47f5890bdd8eadb231b51459d155dfb4afac639baa58599c243851f3ec48929e
x86_64
bsdcpio-3.1.2-14.el7_9.2.x86_64.rpm SHA-256: e7ae995700f9b53fa906a876dd9d071d50a3c789076668107a7e7afebc786016
bsdtar-3.1.2-14.el7_9.2.x86_64.rpm SHA-256: 2cb7930ef072304e0f1900e4725536311b0a7c2da202b3329e571a3a567acbaf
libarchive-3.1.2-14.el7_9.2.i686.rpm SHA-256: 9395539a7b47d0b52f256b0c5c020743f23351d594d0f3db58cdc55e936e7910
libarchive-3.1.2-14.el7_9.2.x86_64.rpm SHA-256: b39261be6fe1fdaf1a0f71baf579728261b4031ad2a953e60cfeadd1636edd31
libarchive-debuginfo-3.1.2-14.el7_9.2.i686.rpm SHA-256: 816ffff79d7f03636586669fca0d1fa75cb3c6ad609b20ff142c2e109e462c9a
libarchive-debuginfo-3.1.2-14.el7_9.2.i686.rpm SHA-256: 816ffff79d7f03636586669fca0d1fa75cb3c6ad609b20ff142c2e109e462c9a
libarchive-debuginfo-3.1.2-14.el7_9.2.x86_64.rpm SHA-256: af9963dbe7a246843ac093741e067a07ca8eb6da1663346439c20d98c05faa35
libarchive-debuginfo-3.1.2-14.el7_9.2.x86_64.rpm SHA-256: af9963dbe7a246843ac093741e067a07ca8eb6da1663346439c20d98c05faa35
libarchive-devel-3.1.2-14.el7_9.2.i686.rpm SHA-256: 7bfc113794a7f279096c8393914f2668ebc42e0bc7317d13ecdef3a5d6961281
libarchive-devel-3.1.2-14.el7_9.2.x86_64.rpm SHA-256: 85912fd0030833d1758010adaa2b55e3adaaf6bfe8605e8b545c8d2400f732fc

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
libarchive-3.1.2-14.el7_9.2.src.rpm SHA-256: 47f5890bdd8eadb231b51459d155dfb4afac639baa58599c243851f3ec48929e
s390x
bsdcpio-3.1.2-14.el7_9.2.s390x.rpm SHA-256: c3f0076a8100b54e08d62b5e1985c285a66ebff1c68860934ba74354140fe129
bsdtar-3.1.2-14.el7_9.2.s390x.rpm SHA-256: bb7c3db6b1285fbdd7af718bafc8918f0d602518b6f5fd8ba9d83c3d84e1bfdf
libarchive-3.1.2-14.el7_9.2.s390.rpm SHA-256: dc1b5ac784e52aefe8c8477b082c2bbbe167f8c8d7778254a6d19187c3a2e733
libarchive-3.1.2-14.el7_9.2.s390x.rpm SHA-256: f419e05d22c18b9dcb0c6435b4f231e06566271c5d0156ceeddc96c1f2e2808c
libarchive-debuginfo-3.1.2-14.el7_9.2.s390.rpm SHA-256: 7ecde9eda3070c24340c09a1b118f15e599f3f524c19ce322d5a481b0630a2e5
libarchive-debuginfo-3.1.2-14.el7_9.2.s390.rpm SHA-256: 7ecde9eda3070c24340c09a1b118f15e599f3f524c19ce322d5a481b0630a2e5
libarchive-debuginfo-3.1.2-14.el7_9.2.s390x.rpm SHA-256: 5f59efbebec836e7905c5c078c393729b26c5d0e1a1cc8fa18ff1f7410ee790a
libarchive-debuginfo-3.1.2-14.el7_9.2.s390x.rpm SHA-256: 5f59efbebec836e7905c5c078c393729b26c5d0e1a1cc8fa18ff1f7410ee790a
libarchive-devel-3.1.2-14.el7_9.2.s390.rpm SHA-256: a43a8600bb503af558e8b128e9c814080671a6fd93f6cc5703056f182426671f
libarchive-devel-3.1.2-14.el7_9.2.s390x.rpm SHA-256: ac05ed1248089894d5c1b7c40f407ceaa30601198763faba4279d892877439ef

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
libarchive-3.1.2-14.el7_9.2.src.rpm SHA-256: 47f5890bdd8eadb231b51459d155dfb4afac639baa58599c243851f3ec48929e
ppc64
bsdcpio-3.1.2-14.el7_9.2.ppc64.rpm SHA-256: 555e267ccd39f6f3099a1c9b5e1b4cfdd91192678dbe785bf42acd0163fda4a8
bsdtar-3.1.2-14.el7_9.2.ppc64.rpm SHA-256: 5a9a064a923732798fb6d72b7ba2784c01213ab8f41421290c27603be5acca5a
libarchive-3.1.2-14.el7_9.2.ppc.rpm SHA-256: 5af70ef7d99ed42e2254ee443c92bc5fe51923585f5f60c3bdd20c8076a8ae0b
libarchive-3.1.2-14.el7_9.2.ppc64.rpm SHA-256: 9935ee0ecf4e056a7f9be3dc594ccc49d550e5ab39d229e65b0307a4cdfcc835
libarchive-debuginfo-3.1.2-14.el7_9.2.ppc.rpm SHA-256: 2af6c554f6f9c3dc523eee5c5f77bd9fe86f8845c76d8b22b7c739ed7685674c
libarchive-debuginfo-3.1.2-14.el7_9.2.ppc.rpm SHA-256: 2af6c554f6f9c3dc523eee5c5f77bd9fe86f8845c76d8b22b7c739ed7685674c
libarchive-debuginfo-3.1.2-14.el7_9.2.ppc64.rpm SHA-256: 3d5cae6b9bfcbce760c8876118b6a9114a1248c20d23815798b00131af20d9d3
libarchive-debuginfo-3.1.2-14.el7_9.2.ppc64.rpm SHA-256: 3d5cae6b9bfcbce760c8876118b6a9114a1248c20d23815798b00131af20d9d3
libarchive-devel-3.1.2-14.el7_9.2.ppc.rpm SHA-256: b82f072071a0babddac66a580a80a22a7a4c7e620be013e2e2355a82796045d6
libarchive-devel-3.1.2-14.el7_9.2.ppc64.rpm SHA-256: fe076135bcf85c840c8a010ee82d4358359453e7e7e933e631ed0fb4a053476c

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
libarchive-3.1.2-14.el7_9.2.src.rpm SHA-256: 47f5890bdd8eadb231b51459d155dfb4afac639baa58599c243851f3ec48929e
ppc64le
bsdcpio-3.1.2-14.el7_9.2.ppc64le.rpm SHA-256: 83d9260b187a2ec7d7bb98f66a244563c54bb1309556bc0d3b50a5fc41d60fed
bsdtar-3.1.2-14.el7_9.2.ppc64le.rpm SHA-256: c2e6072ecf267d2a46a1e0ef093d44a959d2c0494bb817cb3cabbb24a0f16137
libarchive-3.1.2-14.el7_9.2.ppc64le.rpm SHA-256: b5a4498b26ca59e97d1d7938120f803e9c3382025147471bbe296415bd445a90
libarchive-debuginfo-3.1.2-14.el7_9.2.ppc64le.rpm SHA-256: e61c0b01490598729fc55969e8578a487eb4868e172317e91d647867205dafd4
libarchive-debuginfo-3.1.2-14.el7_9.2.ppc64le.rpm SHA-256: e61c0b01490598729fc55969e8578a487eb4868e172317e91d647867205dafd4
libarchive-devel-3.1.2-14.el7_9.2.ppc64le.rpm SHA-256: 3f6d9a14ce5d2775aaef1e8b2d8c8a8e5a2731e3bcc00e3b554b812d2e2e44ae

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility