A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.
CVSS Details
- CVSS 3.1 Base Score: 6.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade libarchive-debugsourceUpgrade bsdcatUpgrade bsdcat-debuginfoUpgrade bsdunzip-debuginfoUpgrade bsdunzipUpgrade bsdcpioUpgrade bsdtar-debuginfoUpgrade bsdcpio-debuginfoUpgrade bsdtarUpgrade libarchiveUpgrade libarchive-develUpgrade libarchive-debuginfo | Jul 30, 2025 | May 20, 2025 |
| Debian | — | Upgrade libarchive | Jun 11, 2025 | Jun 9, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 9, 2025 |
| Suse | — | Upgrade libarchive-develUpgrade bsdtarUpgrade libarchive13-32bitUpgrade libarchive13 | Aug 1, 2025 | Jul 31, 2025 |
| Ubuntu | — | Upgrade libarchive13t64Upgrade libarchive13 | Jun 26, 2025 | Jun 9, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Feb 9, 2026 | Jun 9, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub