CVE-2026-16517: Red Hat Enterprise Linux 10

Low severity, CVSS 2.9. EPSS: 0.1% chance of exploitation in the next 30 days.

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.

Affected products

  • Red Hat Red Hat Enterprise Linux 10: before 0:3.7.7-11.el10_2 (fixed in 0:3.7.7-11.el10_2)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Hardened Images: before 3.8.8-3.1.hum1 (fixed in 3.8.8-3.1.hum1)
  • Red Hat Red Hat Openshift Container Platform 4

Published 2026-07-21. Last modified 2026-09-22.