CVE-2026-15028: Red Hat Cost Management On-Premise 1

Low severity, CVSS 3.9. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.

Affected products

  • Red Hat Red Hat Cost Management On-Premise 1: before 1791460851 (fixed in 1791460851)
  • Red Hat Red Hat Enterprise Linux 10: before 0:3.7.7-11.el10_2 (fixed in 0:3.7.7-11.el10_2)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Hardened Images: before 3.8.8-2.1.hum1 (fixed in 3.8.8-2.1.hum1)
  • Red Hat Red Hat Openshift Container Platform 4

Published 2026-07-10. Last modified 2026-10-09.