PT-2026-63256 · Red Hat · Red Hat Enterprise Linux 10+6

CVE-2026-16517

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v3.1

2.9

Low

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive write zip header function in archive write set format zip.c, when ZIP encryption is enabled and the entry file size is close to INT64 MAX, the addition of the encryption overhead to the entry size overflows int64 t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16517

Affected Products

Red Hat Enterprise Linux 10
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 9
Red Hat Hardened Images
Red Hat Openshift Container Platform 4