# Security issues in libarchive

**URL:** https://discourse.cmake.org/t/security-issues-in-libarchive/7852
**Category:** Development
**Tags:** os:linux
**Created:** [April 7, 2023, 9:04am UTC](https://discourse.cmake.org/t/security-issues-in-libarchive/7852 "2023-04-07T09:04:13Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Changhua\_Luo](https://discourse.cmake.org/user_avatar/discourse.cmake.org/changhua_luo/32/3320_2.png) [@Changhua\_Luo](https://discourse.cmake.org/u/Changhua_Luo)
#### Post date: [April 7, 2023, 9:04am UTC](https://discourse.cmake.org/t/security-issues-in-libarchive/7852/1 "2023-04-07T09:04:13Z")

</div>

Hello, while working with CMake, I discovered that it uses an outdated version of libarchive which has some known security issues. Upon diffing with the latest version of libarchive, I found some patches that fix vulnerabilities in libarchive such as null pointer dereferencing. However, these security patches have not been propagated to CMake yet. I would like to suggest that CMake considers incorporating these patches into its latest version as it would ensure more secure and stable software. Thanks.

If you are interested in reviewing the patches that haven’t been propagated into CMake, here are the links of (some) patches:

- Patch 1: [libarchive: Handle a `calloc` returning NULL (fixes #1754) · libarchive/libarchive@bff38ef · GitHub](https://github.com/libarchive/libarchive/commit/bff38efe8c110469c5080d387bec62a6ca15b1a5)
- Patch 2: [archive\_read\_disk\_posix: fail if unable to alocate memory in tree\_push() · libarchive/libarchive@92d2835 · GitHub](https://github.com/libarchive/libarchive/commit/92d2835fed1e9be1e6fd49949bdef917df577274)

---

<div class="post-metadata">

### Author: ![ben.boeckel](https://discourse.cmake.org/letter_avatar_proxy/v4/letter/b/ea5d25/32.png) [@ben.boeckel](https://discourse.cmake.org/u/ben.boeckel)
#### Post date: [April 24, 2023, 4:42am UTC](https://discourse.cmake.org/t/security-issues-in-libarchive/7852/2 "2023-04-24T04:42:42Z")

</div>

Thanks for the heads up. I’m not 100% familiar with how Brad has the third parties set up in CMake, so I’ll let him get to it when he’s back.

Cc: @brad.king

---

<div class="post-metadata">

### Author: ![brad.king](https://discourse.cmake.org/user_avatar/discourse.cmake.org/brad.king/32/11_2.png) [@brad.king](https://discourse.cmake.org/u/brad.king)
#### Post date: [April 25, 2023, 6:14pm UTC](https://discourse.cmake.org/t/security-issues-in-libarchive/7852/3 "2023-04-25T18:14:15Z")

</div>

[CMake MR 8431](https://gitlab.kitware.com/cmake/cmake/-/merge_requests/8431) updates to libarchive 3.6.2 to get those fixes.
