Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Ubuntu 26.04 LTS libarchive Critical Denial of Service Vuln USN-8581-1

ubuntu
Calendar Grey July 22, 2026
Scroller Ubuntu
Multiple security issues in libarchive can lead to denial of service attacks. Update Ubuntu to mitigate these threats.
Ubuntu announced security updates for libarchive addressing multiple vulnerabilities affecting versions 20.04 to 26.04 LTS, which could lead to denial of service or arbitrary code ...

Summary

Several security issues were fixed in libarchive.

Software Description:

- libarchive: Library to read/write archive files

Details:

It was discovered that libarchive did not properly manage memory when

unpacking certain RAR5 archives, leading to a double free. An attacker

could possibly use this issue to cause a denial of service.

(CVE-2026-14164)

It was discovered that libarchive did not properly validate certain tar

archives, leading to a buffer overflow. A remote attacker could possibly

use this issue to cause a denial of service or execute arbitrary code.

This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15028)

It was discovered that libarchive did not properly validate certain

malformed ACL entries. An attacker could possibly use this issue to cause a

denial of service. (CVE-2026-5745)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
  libarchive-dev                  3.8.5-1ubuntu2.2
  libarchive-tools                3.8.5-1ubuntu2.2
  libarchive13t64                 3.8.5-1ubuntu2.2

Ubuntu 24.04 LTS
  libarchive-dev                  3.7.2-2ubuntu0.8
  libarchive-tools                3.7.2-2ubuntu0.8
  libarchive13t64                 3.7.2-2ubuntu0.8

Ubuntu 22.04 LTS
  libarchive-dev                  3.6.0-1ubuntu1.8
  libarchive-tools                3.6.0-1ubuntu1.8
  libarchive13                    3.6.0-1ubuntu1.8

Ubuntu 20.04 LTS
  libarchive-dev                  3.4.0-2ubuntu1.5+esm3
                                  Available with Ubuntu Pro
  libarchive-tools                3.4.0-2ubuntu1.5+esm3
                                  Available with Ubuntu Pro
  libarchive13                    3.4.0-2ubuntu1.5+esm3
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8581-1

CVE-2026-14164, CVE-2026-15028, CVE-2026-5745

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8581-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.