The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of service (crash) via a crafted file, which triggers an invalid read in the (1) detect_form or (2) bid_entry function in libarchive/archive_read_support_format_mtree.c.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-libarchive | Mar 31, 2017 | Oct 17, 2016 | |
| F5 Big Ip | f5-bigip-upgrade-latest | Jun 17, 2026 | Feb 23, 2017 | |
| Gentoo Linux | gentoo-linux-upgrade-app-arch-libarchive | Oct 30, 2017 | Feb 15, 2017 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-libarchive | Dec 4, 2019 | Feb 15, 2017 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-libarchive | Dec 18, 2019 | Feb 15, 2017 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-libarchive | Nov 19, 2019 | Feb 15, 2017 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Sep 15, 2016 | |
| Suse | — | suse-upgrade-bsdtarsuse-upgrade-libarchive-develsuse-upgrade-libarchive13 | Nov 25, 2016 | Nov 25, 2016 |
| Ubuntu | ubuntu-upgrade-libarchive12ubuntu-upgrade-libarchive13 | Mar 10, 2017 | Nov 25, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub