libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libarchive | Aug 8, 2025 | Feb 16, 2025 |
| Oracle_linux | — | Upgrade bsdtarUpgrade libarchive-develUpgrade libarchive | Jul 10, 2025 | Feb 16, 2025 |
| Redhat_linux | — | Upgrade bsdtarUpgrade bsdcpio-debuginfoUpgrade bsdtar-debuginfoUpgrade bsdcat-debuginfoNo solution existsUpgrade bsdunzip-debuginfoUpgrade libarchiveUpgrade libarchive-develUpgrade libarchive-debuginfoUpgrade libarchive-debugsource | Jul 9, 2025 | Feb 16, 2025 |
| Rocky_linux | — | Upgrade libarchiveUpgrade bsdtar-debuginfoUpgrade libarchive-debuginfoUpgrade libarchive-develUpgrade libarchive-debugsourceUpgrade bsdtar | Oct 6, 2025 | Oct 3, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub