CVE-2025-5914
HIGH EPSS 24.3%
Published Jun 9, 20251y ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
Published Jun 9, 2025 1y ago
Last Modified Jun 17, 2026 1w ago
Description
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Attack Vector Local
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
24.3% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available
Weaknesses 1
CWE-190 Integer Overflow or Wraparound Numeric Error
Affected Products 7
References 32
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:14130
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:14135
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:14137
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:14141
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:14142
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:14525
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:14528
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:14594
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:14644
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:14808
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:14810
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:14828
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:15024
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:15397
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:15709
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:15827
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:15828
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:16524
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:18217
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:18218
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:18219
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:19041
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:19046
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:21885
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:21913
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:0326
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:0934
- access.redhat.com https://access.redhat.com/errata/RHSA-2026:1541
- access.redhat.com https://access.redhat.com/security/cve/CVE-2025-5914
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2370861
- github.com https://github.com/libarchive/libarchive/pull/2598
- github.com https://github.com/libarchive/libarchive/releases/tag/v3.8.0
Remediation
- github.com https://github.com/libarchive/libarchive/pull/2598