- What: Security update for libarchive
- Impact: Red Hat Enterprise Linux 10.0 systems
Red Hat Product Errata RHSA-2026:56954 - Security Advisory Issued: 2026-08-19 Updated: 2026-08-19 RHSA-2026:56954 - Security Advisory Overview Updated Packages Synopsis Moderate: libarchive security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libarchive is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The libarchive programming library can create and read several different streaming archive formats, including GNU tar, cpio, and ISO 9660 CD-ROM images. Libarchive is used notably in the bsdtar utility, scripting language bindings such as python-libarchive, and several popular desktop file managers. Security Fix(es): libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() (CVE-2026-14164) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2493411 - CVE-2026-14164 libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() CVEs CVE-2026-14164 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM libarchive-3.7.7-5.el10_0.1.src.rpm SHA-256: 24830a6131de44738b2fb59f3f2ff5939263cebcd83184ff1e13284d04ce4cf4 x86_64 bsdcat-debuginfo-3.7.7-5.el10_0.1.x86_64.rpm SHA-256: d78c7a6e17b788cf88103c343e68f11ca1b225f105f5a549686300766463d2c4 bsdcat-debuginfo-3.7.7-5.el10_0.1.x86_64.rpm SHA-256: d78c7a6e17b788cf88103c343e68f11ca1b225f105f5a549686300766463d2c4 bsdcpio-debuginfo-3.7.7-5.el10_0.1.x86_64.rpm SHA-256: 132f056f56f72fd427bf21413dca229b9bbe7aba1128b07afbcada73fba38e09 bsdcpio-debuginfo-3.7.7-5.el10_0.1.x86_64.rpm SHA-256: 132f056f56f72fd427bf21413dca229b9bbe7aba1128b07afbcada73fba38e09 bsdtar-3.7.7-5.el10_0.1.x86_64.rpm SHA-256: 6b6a6977be032ec592a2ac53b3a3a35d589d922b0cf742f96877d11b97c60f07 bsdtar-debuginfo-3.7.7-5.el10_0.1.x86_64.rpm SHA-256: ef49f2ae165568fad8caa5243133721fa8a3ab516a12bf7d74229e29d4f82f04 bsdtar-debuginfo-3.7.7-5.el10_0.1.x86_64.rpm SHA-256: ef49f2ae165568fad8caa5243133721fa8a3ab516a12bf7d74229e29d4f82f04 bsdunzip-debuginfo-3.7.7-5.el10_0.1.x86_64.rpm SHA-256: 78ab7adce1504637dd94ed6ec9de659cf5a8a8844f8a1ef89643faa8b03486be bsdunzip-debuginfo-3.7.7-5.el10_0.1.x86_64.rpm SHA-256: 78ab7adce1504637dd94ed6ec9de659cf5a8a8844f8a1ef89643faa8b03486be libarchive-3.7.7-5.el10_0.1.x86_64.rpm SHA-256: d3b92acc60fb47eef3c859b79d438595e83d6ecc7a81f6b2ab6ae14830e8cdeb libarchive-debuginfo-3.7.7-5.el10_0.1.x86_64.rpm SHA-256: ea78f40e9ac79dee8cdc5a4e8888f511ea2972a2afb37d8195d856e7148a8894 libarchive-debuginfo-3.7.7-5.el10_0.1.x86_64.rpm SHA-256: ea78f40e9ac79dee8cdc5a4e8888f511ea2972a2afb37d8195d856e7148a8894 libarchive-debugsource-3.7.7-5.el10_0.1.x86_64.rpm SHA-256: ee2c9b3501e51c07c86724f8a5a3f60d3c0ce6ce26f1c436ebb87c69e4129a48 libarchive-debugsource-3.7.7-5.el10_0.1.x86_64.rpm SHA-256: ee2c9b3501e51c07c86724f8a5a3f60d3c0ce6ce26f1c436ebb87c69e4129a48 libarchive-devel-3.7.7-5.el10_0.1.x86_64.rpm SHA-256: e3e37321ab96054189668cdea6cb4557ebfd76312e6742ba0c9775dba86c9bf4 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM libarchive-3.7.7-5.el10_0.1.src.rpm SHA-256: 24830a6131de44738b2fb59f3f2ff5939263cebcd83184ff1e13284d04ce4cf4 s390x bsdcat-debuginfo-3.7.7-5.el10_0.1.s390x.rpm SHA-256: 12c2c714930944e9150ebba0b7422144bc000d44d28012648a7f2987cddb7189 bsdcat-debuginfo-3.7.7-5.el10_0.1.s390x.rpm SHA-256: 12c2c714930944e9150ebba0b7422144bc000d44d28012648a7f2987cddb7189 bsdcpio-debuginfo-3.7.7-5.el10_0.1.s390x.rpm SHA-256: ba80a0d608aa1d054b28e7c4fba7ec3884510f8a41f4ddfeb9f99904e848b581 bsdcpio-debuginfo-3.7.7-5.el10_0.1.s390x.rpm SHA-256: ba80a0d608aa1d054b28e7c4fba7ec3884510f8a41f4ddfeb9f99904e848b581 bsdtar-3.7.7-5.el10_0.1.s390x.rpm SHA-256: 93f34a65eff9eabafeaeaad1a98f295ea6e469a45c68f9664a70fc2fe6c0e773 bsdtar-debuginfo-3.7.7-5.el10_0.1.s390x.rpm SHA-256: e53452a94c92e75b09ac708311f2fd04b983d477f0c298e0f2b87b268b196281 bsdtar-debuginfo-3.7.7-5.el10_0.1.s390x.rpm SHA-256: e53452a94c92e75b09ac708311f2fd04b983d477f0c298e0f2b87b268b196281 bsdunzip-debuginfo-3.7.7-5.el10_0.1.s390x.rpm SHA-256: a3fae63c624a4126a3a406c663c442f156f45434c78b4053d261b965f43181ca bsdunzip-debuginfo-3.7.7-5.el10_0.1.s390x.rpm SHA-256: a3fae63c624a4126a3a406c663c442f156f45434c78b4053d261b965f43181ca libarchive-3.7.7-5.el10_0.1.s390x.rpm SHA-256: 06335b5c585c514c4d011270df65cf572a0281874d3c9ca8000a8651f716f44c libarchive-debuginfo-3.7.7-5.el10_0.1.s390x.rpm SHA-256: 708e9e3c3c834734419e39ce623623b293a5d446fecf05be54c8d700e8cad80d libarchive-debuginfo-3.7.7-5.el10_0.1.s390x.rpm SHA-256: 708e9e3c3c834734419e39ce623623b293a5d446fecf05be54c8d700e8cad80d libarchive-debugsource-3.7.7-5.el10_0.1.s390x.rpm SHA-256: 4ff16080007c1008c89174f41d0caecf4b30d9c814c08612de3fcee9791681f7 libarchive-debugsource-3.7.7-5.el10_0.1.s390x.rpm SHA-256: 4ff16080007c1008c89174f41d0caecf4b30d9c814c08612de3fcee9791681f7 libarchive-devel-3.7.7-5.el10_0.1.s390x.rpm SHA-256: 2d72e952057f2e7523f371c47f70f52caf8763fcb18a659af50548aa0a601e08 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM libarchive-3.7.7-5.el10_0.1.src.rpm SHA-256: 24830a6131de44738b2fb59f3f2ff5939263cebcd83184ff1e13284d04ce4cf4 ppc64le bsdcat-debuginfo-3.7.7-5.el10_0.1.ppc64le.rpm SHA-256: b88b6c67808d61de017227728a8711bd1a25ea5f8c5bdb999d01757288b80d39 bsdcat-debuginfo-3.7.7-5.el10_0.1.ppc64le.rpm SHA-256: b88b6c67808d61de017227728a8711bd1a25ea5f8c5bdb999d01757288b80d39 bsdcpio-debuginfo-3.7.7-5.el10_0.1.ppc64le.rpm SHA-256: 21495b775e7ecf67d0c8c85fef2ab0625c086ddaf51946a95400572e8375897c bsdcpio-debuginfo-3.7.7-5.el10_0.1.ppc64le.rpm SHA-256: 21495b775e7ecf67d0c8c85fef2ab0625c086ddaf51946a95400572e8375897c bsdtar-3.7.7-5.el10_0.1.ppc64le.rpm SHA-256: dd9ee015fc10188d26291fab5f61cf1037d6d0ceee7afdb9115042502f70eff7 bsdtar-debuginfo-3.7.7-5.el10_0.1.ppc64le.rpm SHA-256: 62ce283aa62e91592b5a03cbc08af15a2191c996b33bf50eafcfc493972f0ef2 bsdtar-debuginfo-3.7.7-5.el10_0.1.ppc64le.rpm SHA-256: 62ce283aa62e91592b5a03cbc08af15a2191c996b33bf50eafcfc493972f0ef2 bsdunzip-debuginfo-3.7.7-5.el10_0.1.ppc64le.rpm SHA-256: 93f497c9bd80be78ad17ca0d8f33ca146ffac6eae9ff332cf602274c770060e6 bsdunzip-debuginfo-3.7.7-5.el10_0.1.ppc64le.rpm SHA-256: 93f497c9bd80be78ad17ca0d8f33ca146ffac6eae9ff332cf602274c770060e6 libarchive-3.7.7-5.el10_0.1.ppc64le.rpm SHA-256: c7b0d2b33be9b9c25b4823533ab824a1c27eb9fd6f365b226a8afc2aeb4ac269 libarchive-debuginfo-3.7.7-5.el10_0.1.ppc64le.rpm SHA-256: 42902df4e8ec08ccb645d2a895c6ffaee7229df1dd5b8115560b8a1d6fc9e524 libarchive-debuginfo-3.7.7-5.el10_0.1.ppc64le.rpm SHA-256: 42902df4e8ec08ccb645d2a895c6ffaee7229df1dd5b8115560b8a1d6fc9e524 libarchive-debugsource-3.7.7-5.el10_0.1.ppc64le.rpm SHA-256: 622bb1e3e33ef4ffae009c3c72a6bf0dd39779eabb7ce774679d2bea00a3fc77 libarchive-debugsource-3.7.7-5.el10_0.1.ppc64le.rpm SHA-256: 622bb1e3e33ef4ffae009c3c72a6bf0dd39779eabb7ce774679d2bea00a3fc77 libarchive-devel-3.7.7-5.el10_0.1.ppc64le.rpm SHA-256: 391b4907a08390005906bb9c9bc613468fa1ad15b178ee9d8c12ef91d64c2bf9 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 SRPM libarchive-3.7.7-5.el10_0.1.src.rpm SHA-256: 24830a6131de44738b2fb59f3f2ff5939263cebcd83184ff1e13284d04ce4cf4 aarch64 bsdcat-debuginfo-3.7.7-5.el10_0.1.aarch64.rpm SHA-256: 8d508a6b0f2eac036f53fd2ea1d629c4eb02c50e1bcaaf5033c14e07945aeb1b bsdcat-debuginfo-3.7.7-5.el10_0.1.aarch64.rpm SHA-256: 8d508a6b0f2eac036f53fd2ea1d629c4eb02c50e1bcaaf5033c14e07945aeb1b bsdcpio-debuginfo-3.7.7-5.el10_0.1.aarch64.rpm SHA-256: 49894f498b87aeb29cc71a5837bc1b8670f73118cb21842bf6935eae4cf1a15b bsdcpio-debuginfo-3.7.7-5.el10_0.1.aarch64.rpm SHA-256: 49894f498b87aeb29cc71a5837bc1b8670f73118cb21842bf6935eae4cf1a15b bsdtar-3.7.7-5.el10_0.1.aarch64.rpm SHA-256: 7a7d220bdcb729a0da2bc5c3e73fabc0eebf20f01c17f8ecc68d21558e65b40b bsdtar-debuginfo-3.7.7-5.el10_0.1.aarch64.rpm SHA-256: d9b09a45c915ac66eecde4207c5c164a0981ce2a7b61782882746eb1ae48fcaa bsdtar-debuginfo-3.7.7-5.el10_0.1.aarch64.rpm SHA-256: d9b09a45c915ac66eecde4207c5c164a0981ce2a7b61782882746eb1ae48fcaa bsdunzip-debuginfo-3.7.7-5.el10_0.1.aarch64.rpm SHA-256: df20295b9d9830a4ea7096877330f655baa254815405e5efd609e00f1b8446f8 bsdunzip-debuginfo-3.7.7-5.el10_0.1.aarch64.rpm SHA-256: df20295b9d9830a4ea7096877330f655baa254815405e5efd609e00f1b8446f8 libarchive-3.7.7-5.el10_0.1.aarch64.rpm SHA-256: 72f8c6fe0af9248b695a7ef312d807aafa572227f9edf46f3f0ad1a86013f23b libarchive-debuginfo-3.7.7-5.el10_0.1.aarch64.rpm SHA-256: b1f57a4c0d183bad08aa2fd2f88b656d0bc770b247f5271daa22