Skip to content
Red HatCVE-2026-15028

Red Hat libarchive. This vulnerability: denial of service

Low3.9CVE-2026-15028 · Published Jul 10, 2026 · updated Sep 22, 2026

A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat file_type content: information disclosure
Critical9.3Jul 10
Red Hat: server-side request forgery
Critical9.3Jul 10
Red Hat GStreamer: buffer overflow
High7.1Jul 9
Red Hat GStreamer: buffer overflow
High7.5Jul 9
Red Hat, Inc.: CVE records (CNA): denial of service
Medium6.5Jul 8
Red Hat gorch service template: missing authentication
Medium6.3Jul 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.