This is a version-less RedHat CVE so needs explicit status.
Fix reference: PR/commit listed in [1] backported as [2].
[1] https://security-tracker.debian.org/tracker/CVE-2026-4426
[2] https://github.com/libarchive/libarchive/commit/
ec1bc43156b84e12ff363f39005533e6f7067297
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
RDEPENDS:${PN}-ptest += "bsdtar bsdcpio"
+CVE_STATUS[CVE-2026-4426] = "fixed-version: fixed since 3.8.7"
CVE_STATUS[CVE-2026-5121] = "fixed-version: fixed since 3.8.7"