Alerts This Week
Warning Icon 1 1,213
Alerts This Week
Warning Icon 1 1,213

openSUSE xar Moderate Null Pointer Threat Fix 2026-21153-1

opensuse
Calendar Grey June 30, 2026
Dist Opensuse Esm H88
openSUSE addresses 4 vulnerabilities in xar with this security patch, ensuring system integrity and performance.
An update that solves 4 vulnerabilities and has 4 bug fixes can now be installed.

Description

This update for xar fixes the following issues:

Changes in xar:

- Switch to the maintained Apple xar lineage (build 503, versioned

1.8.0.0.503): the mackyle 1.6.1 fork this package tracked has been

dead since 2012, and Debian, Fedora and Gentoo all moved to Apple's

xar (apple-oss-distributions/xar). This resolves the long-standing

NULL-pointer dereferences in xar_get_path() and xar_unserialize()

when parsing malformed archives:

* CVE-2017-11124 (boo#1047875)

* CVE-2017-11125 (boo#1047874)

* CVE-2018-17093 (boo#1108595)

* CVE-2018-17094 (boo#1108596)

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-packagehub-348=1

Patch

Package List

- openSUSE Leap 16.0:

libxar-devel-1.8.0.0.503-bp160.1.1

libxar1-1.8.0.0.503-bp160.1.1

xar-1.8.0.0.503-bp160.1.1

References

* bsc#1047874

* bsc#1047875

* bsc#1108595

* bsc#1108596

References:

* https://www.suse.com/security/cve/CVE-2017-11124.html

* https://www.suse.com/security/cve/CVE-2017-11125.html

* https://www.suse.com/security/cve/CVE-2018-17093.html

* https://www.suse.com/security/cve/CVE-2018-17094.html

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21153-1
Rating: moderate
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here