libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libarchive | Aug 8, 2025 | Feb 16, 2025 |
| Oracle_linux | — | Upgrade bsdtarUpgrade libarchive-develUpgrade libarchive | Jul 10, 2025 | Feb 16, 2025 |
| Redhat_linux | — | Upgrade bsdcpio-debuginfoUpgrade bsdtar-debuginfoUpgrade bsdunzip-debuginfoUpgrade bsdtarNo solution existsUpgrade libarchiveUpgrade bsdcat-debuginfoUpgrade libarchive-develUpgrade libarchive-debugsourceUpgrade libarchive-debuginfo | Jul 9, 2025 | Feb 16, 2025 |
| Rocky_linux | — | Upgrade bsdtar-debuginfoUpgrade libarchiveUpgrade libarchive-debuginfoUpgrade bsdtarUpgrade libarchive-debugsourceUpgrade libarchive-devel | Oct 6, 2025 | Oct 3, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub