CVE-2026-16517

Publication date 21 July 2026

Last updated 8 October 2026


Ubuntu priority

Cvss 3 Severity Score

2.9 · Low

Score breakdown

Description

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.

Status

Package Ubuntu Release Status
libarchive 26.04 LTS resolute
Fixed 3.8.5-1ubuntu2.3
24.04 LTS noble
Fixed 3.7.2-2ubuntu0.9
22.04 LTS jammy
Fixed 3.6.0-1ubuntu1.9
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation
14.04 LTS trusty
Needs evaluation

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
libarchive

Severity score breakdown

CVSS version: CVSS v3.0

Base score 2.9 · Low

Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

References

Related Ubuntu Security Notices (USN)

    • USN-8902-1
    • libarchive vulnerability
    • 8 October 2026

Other references


Access our resources on patching vulnerabilities