Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
This update includes the following RPMs: libarchive: * bsdcat-3.8.8-2.1.hum1 (aarch64, x86_64) * bsdcpio-3.8.8-2.1.hum1 (aarch64, x86_64) * bsdtar-3.8.8-2.1.hum1 (aarch64, x86_64) * bsdunzip-3.8.8-2.1.hum1 (aarch64, x86_64) * libarchive-3.8.8-2.1.hum1 (aarch64, x86_64) * libarchive-devel-3.8.8-2.1.hum1 (aarch64, x86_64) * libarchive-3.8.8-2.1.hum1.src (src) Security Fix(es): libarchive: * CVE-2026-15028
AI Analysis
Technical Summary
CVE-2026-15028 is a heap overflow vulnerability in libarchive that can be triggered by parsing a malicious tar archive with a malformed PAX extended header containing a SUN.holesdata sparse-file attribute. This flaw can lead to denial of service or, in complex scenarios, arbitrary code execution. Exploitation requires that a user or automated system actively parses the crafted archive using libarchive, meaning the attacker cannot trigger it remotely without interaction. The vulnerability affects libarchive versions included in Red Hat Hardened Images RPMs for aarch64 and x86_64 architectures. Red Hat has issued updated packages (version 3.8.8-2.1.hum1) to fix this issue. The CVSS v3.1 base score assigned by Red Hat is 3.9 (medium severity), reflecting local attack vector with low privileges required and user interaction needed.
Potential Impact
The vulnerability can cause a denial of service by crashing applications that parse the malicious tar archive. In some cases, it may allow an attacker to execute arbitrary code, potentially gaining control over the affected system. However, reliable exploitation for code execution is complex and depends on the memory layout and protections of the target application. The attack requires user interaction or a specific application workflow to process the crafted archive, limiting remote exploitation capabilities.
Mitigation Recommendations
Red Hat has released updated libarchive RPM packages (version 3.8.8-2.1.hum1) for affected architectures to address this vulnerability. Users should apply these updates as soon as possible. Until patched, avoid processing untrusted or unverified tar archives, especially those from unknown sources or with unexpected content. Exercise caution when handling such archives to prevent triggering the vulnerability.
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Description
This update includes the following RPMs: libarchive: * bsdcat-3.8.8-2.1.hum1 (aarch64, x86_64) * bsdcpio-3.8.8-2.1.hum1 (aarch64, x86_64) * bsdtar-3.8.8-2.1.hum1 (aarch64, x86_64) * bsdunzip-3.8.8-2.1.hum1 (aarch64, x86_64) * libarchive-3.8.8-2.1.hum1 (aarch64, x86_64) * libarchive-devel-3.8.8-2.1.hum1 (aarch64, x86_64) * libarchive-3.8.8-2.1.hum1.src (src) Security Fix(es): libarchive: * CVE-2026-15028
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-15028 is a heap overflow vulnerability in libarchive that can be triggered by parsing a malicious tar archive with a malformed PAX extended header containing a SUN.holesdata sparse-file attribute. This flaw can lead to denial of service or, in complex scenarios, arbitrary code execution. Exploitation requires that a user or automated system actively parses the crafted archive using libarchive, meaning the attacker cannot trigger it remotely without interaction. The vulnerability affects libarchive versions included in Red Hat Hardened Images RPMs for aarch64 and x86_64 architectures. Red Hat has issued updated packages (version 3.8.8-2.1.hum1) to fix this issue. The CVSS v3.1 base score assigned by Red Hat is 3.9 (medium severity), reflecting local attack vector with low privileges required and user interaction needed.
Potential Impact
The vulnerability can cause a denial of service by crashing applications that parse the malicious tar archive. In some cases, it may allow an attacker to execute arbitrary code, potentially gaining control over the affected system. However, reliable exploitation for code execution is complex and depends on the memory layout and protections of the target application. The attack requires user interaction or a specific application workflow to process the crafted archive, limiting remote exploitation capabilities.
Mitigation Recommendations
Red Hat has released updated libarchive RPM packages (version 3.8.8-2.1.hum1) for affected architectures to address this vulnerability. Users should apply these updates as soon as possible. Until patched, avoid processing untrusted or unverified tar archives, especially those from unknown sources or with unexpected content. Exercise caution when handling such archives to prevent triggering the vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:38279
- Cve Count
- 1
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a54adf168715ace438f6cd4
Added to database: 07/13/2026, 09:20:49 UTC
Last enriched: 08/13/2026, 20:28:29 UTC
Last updated: 09/12/2026, 22:01:31 UTC
Views: 619
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.