Description
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.
Problem types
Integer Overflow or Wraparound
Product status
Any version before 3.8.0
0:3.7.7-4.el10_0 (rpm) before *
0:3.1.2-14.el7_9.1 (rpm) before *
0:3.3.3-6.el8_10 (rpm) before *
0:3.3.2-8.el8_2.1 (rpm) before *
0:3.3.3-1.el8_4.1 (rpm) before *
0:3.3.3-1.el8_4.1 (rpm) before *
0:3.3.3-6.el8_6 (rpm) before *
0:3.3.3-6.el8_6 (rpm) before *
0:3.3.3-6.el8_6 (rpm) before *
0:3.3.3-5.el8_8.1 (rpm) before *
0:3.3.3-5.el8_8.1 (rpm) before *
0:3.5.3-6.el9_6 (rpm) before *
0:3.5.3-6.el9_6 (rpm) before *
0:3.5.3-2.el9_0.1 (rpm) before *
0:3.5.3-5.el9_2 (rpm) before *
0:3.5.3-4.el9_4.1 (rpm) before *
414.92.202510211419-0 (rpm) before *
415.92.202601271320-0 (rpm) before *
416.94.202601071926-0 (rpm) before *
417.94.202510112152-0 (rpm) before *
418.94.202510230424-0 (rpm) before *
4.19.9.6.202510140714-0 (rpm) before *
4.20.9.6.202509251656-0 (rpm) before *
1.11-19 (rpm) before *
1.11-8 (rpm) before *
1.12-4 (rpm) before *
1.36.0-11 (rpm) before *
1.36.0-11 (rpm) before *
1.36.0-11 (rpm) before *
1.36.0-10 (rpm) before *
1.36.0-10 (rpm) before *
1.36.0-4 (rpm) before *
1.36.0-9 (rpm) before *
1.36.0-12 (rpm) before *
1.36.0-18 (rpm) before *
1.36.0-11 (rpm) before *
1.36.0-7 (rpm) before *
v1.16.5-1760515757 (rpm) before *
v1.3 (rpm) before *
1.8.0 (rpm) before *
1.8.0 (rpm) before *
1.8.0 (rpm) before *
2.2.1-1758555934 (rpm) before *
1.5.6-1756187445 (rpm) before *
rhosdt-3.5-1756116455 (rpm) before *
rhosdt-3.5-1756116482 (rpm) before *
rhosdt-3.5-1756116441 (rpm) before *
rhosdt-3.5-1756116449 (rpm) before *
rhosdt-3.5-1756116439 (rpm) before *
rhosdt-3.5-1756116447 (rpm) before *
rhosdt-3.5-1756128595 (rpm) before *
rhosdt-3.5-1756125872 (rpm) before *
rhosdt-3.5-1756116445 (rpm) before *
1.10.2-1757422110 (rpm) before *
1.10.2-1757421846 (rpm) before *
1.10.2-1757421804 (rpm) before *
1.10.2-1757422070 (rpm) before *
1.10.2-1757421879 (rpm) before *
1.10.2-1757422401 (rpm) before *
1.10.2-1757421890 (rpm) before *
Timeline
| 2025-06-06: | Reported to Red Hat. |
| 2025-05-20: | Made public. |
References
github.com/libarchive/libarchive/pull/2598
access.redhat.com/errata/RHSA-2025:14130 (RHSA-2025:14130)
access.redhat.com/errata/RHSA-2025:14135 (RHSA-2025:14135)
access.redhat.com/errata/RHSA-2025:14137 (RHSA-2025:14137)
access.redhat.com/errata/RHSA-2025:14141 (RHSA-2025:14141)
access.redhat.com/errata/RHSA-2025:14142 (RHSA-2025:14142)
access.redhat.com/errata/RHSA-2025:14525 (RHSA-2025:14525)
access.redhat.com/errata/RHSA-2025:14528 (RHSA-2025:14528)
access.redhat.com/errata/RHSA-2025:14594 (RHSA-2025:14594)
access.redhat.com/errata/RHSA-2025:14644 (RHSA-2025:14644)
access.redhat.com/errata/RHSA-2025:14808 (RHSA-2025:14808)
access.redhat.com/errata/RHSA-2025:14810 (RHSA-2025:14810)
access.redhat.com/errata/RHSA-2025:14828 (RHSA-2025:14828)
access.redhat.com/errata/RHSA-2025:15024 (RHSA-2025:15024)
access.redhat.com/errata/RHSA-2025:15397 (RHSA-2025:15397)
access.redhat.com/errata/RHSA-2025:15709 (RHSA-2025:15709)
access.redhat.com/errata/RHSA-2025:15827 (RHSA-2025:15827)
access.redhat.com/errata/RHSA-2025:15828 (RHSA-2025:15828)
access.redhat.com/errata/RHSA-2025:16524 (RHSA-2025:16524)
access.redhat.com/errata/RHSA-2025:18217 (RHSA-2025:18217)
access.redhat.com/errata/RHSA-2025:18218 (RHSA-2025:18218)
access.redhat.com/errata/RHSA-2025:18219 (RHSA-2025:18219)
access.redhat.com/errata/RHSA-2025:19041 (RHSA-2025:19041)
access.redhat.com/errata/RHSA-2025:19046 (RHSA-2025:19046)
access.redhat.com/errata/RHSA-2025:21885 (RHSA-2025:21885)
access.redhat.com/errata/RHSA-2025:21913 (RHSA-2025:21913)
access.redhat.com/errata/RHSA-2026:0326 (RHSA-2026:0326)
access.redhat.com/errata/RHSA-2026:0934 (RHSA-2026:0934)
access.redhat.com/errata/RHSA-2026:1541 (RHSA-2026:1541)
access.redhat.com/security/cve/CVE-2025-5914
bugzilla.redhat.com/show_bug.cgi?id=2370861 (RHBZ#2370861)
github.com/libarchive/libarchive/pull/2598
github.com/libarchive/libarchive/releases/tag/v3.8.0