Description
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- libarchive / libarchive3.8.0
- RedHat / enterprise_linux6.0 – 6.0
- RedHat / enterprise_linux7.0 – 7.0
- RedHat / enterprise_linux10.0 – 10.0
- RedHat / enterprise_linux8.0 – 8.0
- RedHat / enterprise_linux9.0 – 9.0
- RedHat / openshift_container_platform4.0 – 4.0
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:14130
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:14135
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:14137
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:14141
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:14142
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:14525
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:14528
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:14594
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:14644
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:14808
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:14810
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:14828
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:15024
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:15397
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:15709
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:15827
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:15828
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:16524
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:18217
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:18218
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:18219
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:19041
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:19046
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:21885
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:21913
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:0326
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:0934
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:1541
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2025-5914
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2370861
- PATCHhttps://github.com/libarchive/libarchive/pull/2598
- PATCHhttps://github.com/libarchive/libarchive/releases/tag/v3.8.0
Updated 13m ago · 8 sources