Undefined behaviour (signed integer overflow) was found in libarchive, in the TAR parser. Upstream bug: https://github.com/libarchive/libarchive/issues/548 Upstream fix: https://github.com/libarchive/libarchive/commit/3c7a6dc
Created libarchive tracking bugs for this issue: Affects: fedora-all [bug 1352776] Affects: epel-5 [bug 1352775]