A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.
CVSS Details
- CVSS 3.1 Base Score: 5.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libarchive | Jun 11, 2025 | Jun 9, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade libarchive | Sep 15, 2025 | Aug 9, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade libarchive | Aug 13, 2025 | Aug 9, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade libarchive | Sep 15, 2025 | Aug 9, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade libarchive | Sep 25, 2025 | Aug 9, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 9, 2025 |
| Suse | — | Upgrade libarchive13-32bitUpgrade xtrabackupUpgrade libarchive13Upgrade xtrabackup-testUpgrade rpi-imagerUpgrade bsdtarUpgrade libarchive-devel | Jun 30, 2025 | Jun 9, 2025 |
| Ubuntu | — | Upgrade bsdtar (Ubuntu Pro)Upgrade libarchive-tools (Ubuntu Pro)Upgrade libarchive13 (Ubuntu Pro)Upgrade bsdcpio (Ubuntu Pro)Upgrade libarchive13Upgrade libarchive13t64Upgrade libarchive-dev (Ubuntu Pro) | Jun 26, 2025 | Jun 9, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Feb 9, 2026 | Jun 9, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub