Low severity3.9NVD Advisory· Published Jul 10, 2026· Updated Oct 9, 2026
CVE-2026-15028
CVE-2026-15028
Description
A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- osv-coords3 versions
< 3.7.7-11.el10_2+ 2 more
- (no CPE)range: < 3.7.7-11.el10_2
- (no CPE)range: < 3.7.7-11.el10_2
- (no CPE)range: < 3.7.7-11.el10_2
Patches
Vulnerability mechanics
References
7- access.redhat.com/errata/RHSA-2026:38279nvd
- access.redhat.com/errata/RHSA-2026:69553nvd
- access.redhat.com/errata/RHSA-2026:79357nvd
- access.redhat.com/security/cve/CVE-2026-15028nvd
- bugzilla.redhat.com/show_bug.cginvd
- github.com/libarchive/libarchive/issues/3251nvd
- github.com/libarchive/libarchive/pull/3253nvd
News mentions
0No linked articles in our index yet.