PT-2026-63256 · Red Hat · Red Hat Enterprise Linux 10+6

CVE-2026-16517

·

Publicado

2026-07-21

·

Atualizado

2026-07-21

CVSS v3.1

2.9

Baixa

VetorAV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive write zip header function in archive write set format zip.c, when ZIP encryption is enabled and the entry file size is close to INT64 MAX, the addition of the encryption overhead to the entry size overflows int64 t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.

Correção

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-16517

Produtos afetados

Red Hat Enterprise Linux 10
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 9
Red Hat Hardened Images
Red Hat Openshift Container Platform 4