Alerts This Week
Warning Icon 1 745
Alerts This Week
Warning Icon 1 745

openSUSE libarchive Important DoS and Info Disclosure Updates 2026-2490-1

opensuse
Calendar Grey June 22, 2026
Dist Opensuse Esm H88
This update addresses critical issues in libarchive for openSUSE ensuring enhanced security against multiple risks.
An update that solves five vulnerabilities can now be installed.

Description

This update for libarchive fixes the following issues

* CVE-2025-60753: bsdtar hangs and OOMs with zero-length pattern matches

(bsc#1253088).

* CVE-2026-4111: logical deadlock the RAR5 filter subsystem and the half-

window output limiter leads to infinite loop and DoS (bsc#1259635).

* CVE-2026-4424: information disclosure via heap out-of-bounds read in RAR

archive processing (bsc#1259928).

* CVE-2026-4426: undefined behavior due to unvalidated operand in shift

expression of the zisofs decompression code (bsc#1259931).

* CVE-2026-5121: arbitrary code execution via integer overflow in ISO9660

image processing (bsc#1261186).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* Development Tools Module 15-SP7

zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2490=1

* Basesystem Module 15-SP7

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2490=1

* SUSE Linux Enterprise Server 15 SP6 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2490=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2490=1

* openSUSE Leap 15.6

zypper in -t patch SUSE-2026-2490=1

Package List

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)

* libarchive13-3.7.2-150600.3.20.1

* bsdtar-debuginfo-3.7.2-150600.3.20.1

* libarchive-devel-3.7.2-150600.3.20.1

* libarchive13-debuginfo-3.7.2-150600.3.20.1

* bsdtar-3.7.2-150600.3.20.1

* libarchive-debugsource-3.7.2-150600.3.20.1

* openSUSE Leap 15.6 (x86_64)

* libarchive13-32bit-debuginfo-3.7.2-150600.3.20.1

* libarchive13-32bit-3.7.2-150600.3.20.1

* openSUSE Leap 15.6 (aarch64_ilp32)

* libarchive13-64bit-3.7.2-150600.3.20.1

* libarchive13-64bit-debuginfo-3.7.2-150600.3.20.1

* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)

* libarchive13-3.7.2-150600.3.20.1

* bsdtar-debuginfo-3.7.2-150600.3.20.1

* libarchive-devel-3.7.2-150600.3.20.1

* libarchive13-debuginfo-3.7.2-150600.3.20.1

* bsdtar-3.7.2-150600.3.20.1

* libarchive-debugsource-3.7.2-150600.3.20.1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)

* libarchive13-3.7.2-150600.3.20.1

* bsdtar-debuginfo-3.7.2-150600.3.20.1

*...

Read the Full Advisory

References

* bsc#1253088

* bsc#1259635

* bsc#1259928

* bsc#1259931

* bsc#1261186

## References:

* https://www.suse.com/security/cve/CVE-2025-60753.html

* https://www.suse.com/security/cve/CVE-2026-4111.html

* https://www.suse.com/security/cve/CVE-2026-4424.html

* https://www.suse.com/security/cve/CVE-2026-4426.html

* https://www.suse.com/security/cve/CVE-2026-5121.html

* https://bugzilla.suse.com/show_bug.cgi?id=1253088

* https://bugzilla.suse.com/show_bug.cgi?id=1259635

* https://bugzilla.suse.com/show_bug.cgi?id=1259928

* https://bugzilla.suse.com/show_bug.cgi?id=1259931

* https://bugzilla.suse.com/show_bug.cgi?id=1261186

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2490-1
Release Date: 2026-06-22T12:34:32Z
Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here