libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libarchive | Aug 8, 2025 | Feb 16, 2025 |
| Oracle_linux | — | Upgrade libarchiveUpgrade bsdtarUpgrade libarchive-devel | Jul 10, 2025 | Feb 16, 2025 |
| Redhat_linux | — | Upgrade libarchiveUpgrade bsdcat-debuginfoUpgrade bsdtar-debuginfoUpgrade bsdcpio-debuginfoNo solution existsUpgrade bsdunzip-debuginfoUpgrade bsdtarUpgrade libarchive-debugsourceUpgrade libarchive-develUpgrade libarchive-debuginfo | Jul 9, 2025 | Feb 16, 2025 |
| Rocky_linux | — | Upgrade libarchive-debuginfoUpgrade libarchiveUpgrade bsdtar-debuginfoUpgrade libarchive-develUpgrade bsdtarUpgrade libarchive-debugsource | Oct 6, 2025 | Oct 3, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub