CVE-2025-5914
גבוהה 7.8
תיאור (מקור, אנגלית)
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-26/7/2026
- CWE
- CWE-190
מוצרים מושפעים
libarchive: libarchive; redhat: openshift container platform; redhat: enterprise linux
קישורים
- https://github.com/libarchive/libarchive/pull/2598 ExploitIssue TrackingPatch
- https://github.com/libarchive/libarchive/pull/2598 ExploitIssue TrackingPatch
- https://access.redhat.com/errata/RHSA-2025:14130 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14135 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14137 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14141 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14142 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14525 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14528 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14594 Third Party Advisory