PatchSiren cyber security CVE debrief
CVE-2016-8687 Libarchive CVE debrief
CVE-2016-8687 is a memory-safety flaw in libarchive that can be triggered when archive-processing code handles a crafted filename containing a non-printable multibyte character. According to the NVD record, the bug can lead to a stack-based buffer overflow and a denial of service. The issue was publicly recorded on 2017-02-15, with patch and advisory references already present in 2016.
- Vendor
- Libarchive
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-15
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-15
- Advisory updated
- 2026-05-13
Who should care
Security teams and maintainers responsible for libarchive deployments, downstream packages, archive extraction/listing tools such as bsdtar, and any application that processes untrusted archives or filenames.
Technical summary
NVD describes the issue as a stack-based buffer overflow in safe_fprintf within tar/util.c in libarchive 3.2.1, mapped to CWE-119. The CVSS v3.0 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating a remotely reachable availability impact with no confidentiality or integrity impact recorded in the advisory. NVD also lists affected CPEs for libarchive 3.2.1 and an openSUSE Leap 42.2 entry, plus references to upstream patch material and third-party advisories.
Defensive priority
High
Recommended defensive actions
- Upgrade libarchive to a version that includes the upstream fix and apply any vendor security updates for packaged distributions.
- Inventory products and services that bundle or statically link libarchive, then rebuild or redeploy them with patched libraries.
- Prioritize testing of archive-processing paths that accept attacker-controlled filenames or extracted metadata, especially where multibyte or non-printable characters may appear.
- Use vendor and distribution advisories linked from the CVE record to confirm backported fixes in your environment.
- Add regression coverage for archive listing and extraction workflows so fixed builds continue to reject or safely handle malformed filenames.
Evidence notes
Source evidence is limited to the supplied NVD/CVE record and its linked references. The NVD record states the vulnerability, CVSS vector, weakness classification, affected CPEs, and references to an upstream GitHub commit, an oss-security mailing list post, and third-party advisories. No exploit code or reproduction details are included here.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-8687 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-8687
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-8687 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-8687
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://blogs.gentoo.org/ago/2016/09/11/libarchive-bsdtar-stack-based-buffer-overflow-in-bsdtar_expand_char-util-c/
[email protected] - Patch, Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/libarchive/libarchive/commit/e37b620fe8f14535d737e89a4dcabaed4517bf1a
[email protected] - Issue Tracking, Patch, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.