A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.
CVSS Details
- CVSS 3.1 Base Score: 5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade bsdtarUpgrade libarchive-develUpgrade libarchive-debuginfoUpgrade bsdcpioUpgrade libarchive | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade bsdtarUpgrade libarchive-develUpgrade bsdunzipUpgrade bsdcpio-debuginfoUpgrade libarchive-debugsourceUpgrade bsdcatUpgrade bsdtar-debuginfoUpgrade bsdunzip-debuginfoUpgrade libarchiveUpgrade bsdcat-debuginfoUpgrade bsdcpioUpgrade libarchive-debuginfo | Jul 30, 2025 | May 20, 2025 |
| Debian | — | Upgrade libarchive | Jun 11, 2025 | Jun 9, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade libarchive | Sep 15, 2025 | Aug 9, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade libarchive | Aug 13, 2025 | Aug 9, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade libarchive | Sep 15, 2025 | Aug 9, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade libarchive | Sep 25, 2025 | Aug 9, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 9, 2025 |
| Suse | — | Upgrade libarchive13-32bitUpgrade xtrabackupUpgrade bsdtarUpgrade xtrabackup-testUpgrade libarchive13Upgrade libarchive-devel | Jun 30, 2025 | Jun 9, 2025 |
| Ubuntu | — | Upgrade libarchive13Upgrade libarchive13 (Ubuntu Pro)Upgrade bsdcpio (Ubuntu Pro)Upgrade libarchive-tools (Ubuntu Pro)Upgrade libarchive-devUpgrade libarchive13t64Upgrade libarchive-dev (Ubuntu Pro)Upgrade bsdtar (Ubuntu Pro)Upgrade libarchive-tools | Jun 26, 2025 | Jun 9, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Feb 9, 2026 | Jun 9, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub