A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
CVSS Details
- CVSS 3.1 Base Score: 6.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Libarchive | — | Upgrade macOS to the latest version | Dec 15, 2025 | Dec 15, 2025 |
| Debian | — | Upgrade libarchive | Jun 11, 2025 | Jun 9, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade libarchive | Sep 15, 2025 | Aug 9, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade libarchive | Aug 13, 2025 | Aug 9, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade libarchive | Sep 15, 2025 | Aug 9, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade libarchive | Sep 25, 2025 | Aug 9, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 9, 2025 |
| Suse | — | Upgrade bsdtarUpgrade libarchive-develUpgrade libarchive13-32bitUpgrade libarchive13 | Aug 1, 2025 | Jul 31, 2025 |
| Ubuntu | — | Upgrade libarchive13Upgrade libarchive13 (Ubuntu Pro)Upgrade bsdtar (Ubuntu Pro)Upgrade libarchive-dev (Ubuntu Pro)Upgrade libarchive13t64Upgrade bsdcpio (Ubuntu Pro)Upgrade libarchive-toolsUpgrade libarchive-tools (Ubuntu Pro)Upgrade libarchive-dev | Apr 7, 2026 | Apr 2, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Feb 9, 2026 | Jun 9, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub