A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.
CVSS Details
- CVSS 3.1 Base Score: 5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libarchive-develUpgrade bsdtarUpgrade libarchive-debuginfoUpgrade libarchiveUpgrade bsdcpio | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade bsdunzip-debuginfoUpgrade bsdcatUpgrade bsdtar-debuginfoUpgrade libarchive-develUpgrade bsdcpio-debuginfoUpgrade libarchive-debugsourceUpgrade bsdunzipUpgrade bsdtarUpgrade bsdcpioUpgrade bsdcat-debuginfoUpgrade libarchiveUpgrade libarchive-debuginfo | Jul 30, 2025 | May 20, 2025 |
| Debian | — | Upgrade libarchive | Jun 11, 2025 | Jun 9, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade libarchive | Sep 15, 2025 | Aug 9, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade libarchive | Aug 13, 2025 | Aug 9, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade libarchive | Sep 15, 2025 | Aug 9, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade libarchive | Sep 25, 2025 | Aug 9, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 9, 2025 |
| Suse | — | Upgrade bsdtarUpgrade libarchive13Upgrade xtrabackup-testUpgrade libarchive-develUpgrade xtrabackupUpgrade libarchive13-32bit | Jun 30, 2025 | Jun 9, 2025 |
| Ubuntu | — | Upgrade bsdcpio (Ubuntu Pro)Upgrade libarchive13Upgrade libarchive13t64Upgrade libarchive-devUpgrade libarchive13 (Ubuntu Pro)Upgrade libarchive-tools (Ubuntu Pro)Upgrade libarchive-toolsUpgrade bsdtar (Ubuntu Pro)Upgrade libarchive-dev (Ubuntu Pro) | Jun 26, 2025 | Jun 9, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Feb 9, 2026 | Jun 9, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub