CVE-2025-5914

HIGH EPSS 24.3%
Published Jun 9, 20251y ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published Jun 9, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
24.3% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available

Weaknesses 1

CWE-190 Integer Overflow or Wraparound Numeric Error

Affected Products 7

VendorProductVersionRange
libarchivelibarchive* <3.8.0
redhatopenshift_container_platform4.0any
redhatenterprise_linux6.0any
redhatenterprise_linux7.0any
redhatenterprise_linux8.0any
redhatenterprise_linux9.0any
redhatenterprise_linux10.0any

References 32

  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:14130
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:14135
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:14137
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:14141
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:14142
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:14525
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:14528
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:14594
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:14644
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:14808
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:14810
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:14828
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:15024
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:15397
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:15709
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:15827
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:15828
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:16524
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:18217
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:18218
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:18219
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:19041
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:19046
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:21885
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2025:21913
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2026:0326
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2026:0934
  • access.redhat.com https://access.redhat.com/errata/RHSA-2026:1541
  • access.redhat.com https://access.redhat.com/security/cve/CVE-2025-5914
    Third Party Advisory
  • bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2370861
    Issue TrackingThird Party Advisory
  • github.com https://github.com/libarchive/libarchive/pull/2598
    ExploitIssue TrackingPatch
  • github.com https://github.com/libarchive/libarchive/releases/tag/v3.8.0
    Release Notes

Remediation

  • github.com https://github.com/libarchive/libarchive/pull/2598
    ExploitIssue TrackingPatch