CVE-2026-16517: Integer Overflow or Wraparound in Red Hat Red Hat Hardened Images
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.
AI Analysis
Technical Summary
CVE-2026-16517 is a signed integer overflow vulnerability in the archive_write_zip_header function of libarchive's ZIP writer component. When ZIP encryption is enabled and the entry file size is near INT64_MAX, adding encryption overhead causes an int64_t overflow, leading to undefined behavior. This may result in incorrect Zip64 extension decisions or memory corruption. Red Hat rates this issue as low severity because it affects only the ZIP write path under very specific conditions that are unlikely to occur in practice. The vulnerability is addressed in updated libarchive RPMs for Red Hat Hardened Images.
Potential Impact
The vulnerability can cause undefined behavior including potential memory corruption or application crashes when processing ZIP archives with encryption enabled and extremely large file sizes near INT64_MAX. However, the conditions required are highly contrived, making practical exploitation unlikely. The impact is limited to availability (possible crashes) with no confidentiality or integrity loss expected under normal circumstances.
Mitigation Recommendations
Red Hat has released updated RPM packages for libarchive as part of the Red Hat Hardened Images security update that address CVE-2026-16517. Users should apply these updates to mitigate the vulnerability. Since the vulnerability requires ZIP encryption enabled and extremely large file sizes, if these conditions are not met, the risk is minimal. No additional mitigations are specified by Red Hat.
CVE-2026-16517: Integer Overflow or Wraparound in Red Hat Red Hat Hardened Images
Description
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.
CVSS v3.1
Score 2.9low
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-16517 is a signed integer overflow vulnerability in the archive_write_zip_header function of libarchive's ZIP writer component. When ZIP encryption is enabled and the entry file size is near INT64_MAX, adding encryption overhead causes an int64_t overflow, leading to undefined behavior. This may result in incorrect Zip64 extension decisions or memory corruption. Red Hat rates this issue as low severity because it affects only the ZIP write path under very specific conditions that are unlikely to occur in practice. The vulnerability is addressed in updated libarchive RPMs for Red Hat Hardened Images.
Potential Impact
The vulnerability can cause undefined behavior including potential memory corruption or application crashes when processing ZIP archives with encryption enabled and extremely large file sizes near INT64_MAX. However, the conditions required are highly contrived, making practical exploitation unlikely. The impact is limited to availability (possible crashes) with no confidentiality or integrity loss expected under normal circumstances.
Mitigation Recommendations
Red Hat has released updated RPM packages for libarchive as part of the Red Hat Hardened Images security update that address CVE-2026-16517. Users should apply these updates to mitigate the vulnerability. Since the vulnerability requires ZIP encryption enabled and extremely large file sizes, if these conditions are not met, the risk is minimal. No additional mitigations are specified by Red Hat.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:43818
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- null
Threat ID: 6a6151299c2644c7f8da6ddc
Added to database: 07/22/2026, 23:24:25 UTC
Last enriched: 08/16/2026, 18:05:17 UTC
Last updated: 09/03/2026, 22:52:09 UTC
Views: 88
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.