ELA-790-1 libarchive security update

null pointer dereference

2023-01-31
Packagelibarchive
Version3.1.2-11+deb8u10 (jessie), 3.2.2-2+deb9u4 (stretch)
Related CVEs CVE-2022-36227


An issue has been found in libarchive, a multi-format archive and compression library. Due to missing checks after calloc, null pointer dereferences might happen.



For Debian 8 jessie, these problems have been fixed in version 3.1.2-11+deb8u10.

For Debian 9 stretch, these problems have been fixed in version 3.2.2-2+deb9u4.

We recommend that you upgrade your libarchive packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.