[CLSA-2026:1789483920] Fix CVE(s): CVE-2025-25724
Type:
security
Severity:
Important
Release date:
2026-09-15 14:52:11 UTC
Description:
* SECURITY UPDATE: Use of undefined buffer content in bsdtar verbose listing - debian/patches/CVE-2025-25724.patch: check the strftime return value and the localtime result in list_item_verbose in tar/util.c, printing "-- -- ----" instead of undefined buffer content - CVE-2025-25724
CVEs fixed:
Updated packages:
  • libarchive-dev_3.4.3-2+deb11u5+tuxcare.els1_amd64.deb
    sha:b6760178cbec620652d2a552c4e57dc4c7c55ce7
  • libarchive-tools_3.4.3-2+deb11u5+tuxcare.els1_amd64.deb
    sha:4d0ef563bec28f316e3b14d69bf714dc6044a63d
  • libarchive13_3.4.3-2+deb11u5+tuxcare.els1_amd64.deb
    sha:775a22cff3e735350d7380ffb3b546d26343d774
  • libarchive-dev_3.4.3-2+deb11u5+tuxcare.els1_arm64.deb
    sha:692ed25a6baf1035d5f6a99b38bbae7555ce79bd
  • libarchive-tools_3.4.3-2+deb11u5+tuxcare.els1_arm64.deb
    sha:ff7c6cf82e18cb054cfebc3fb54d2b9bf6521680
  • libarchive13_3.4.3-2+deb11u5+tuxcare.els1_arm64.deb
    sha:9783ef3c55a705630b0d81adbe3bfa274c31f7af
  • libarchive-dev_3.4.3-2+deb11u5+tuxcare.els1_armel.deb
    sha:bd4b2c9b1037a7239c716ed8124e0b0feeeba259
  • libarchive-tools_3.4.3-2+deb11u5+tuxcare.els1_armel.deb
    sha:397cfe81b05a12a4f8570b3d335641d901a8913a
  • libarchive13_3.4.3-2+deb11u5+tuxcare.els1_armel.deb
    sha:e7c2126a8adae97c82d43af01e0a505cf972eeea
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.