← Back

CVE-2025-5915

nvd nist
Published: Jun 9, 2025Modified: Jun 30, 2026

JSON object

Loading...
6.6
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
Exploitability: 1.3 / Impact: 5.2
Source: NVD (Secondary)

Description

A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.

Affected (7)

1 product
Libarchive
2 products
Enterprise Linux
Openshift Container Platform
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.8.0
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 10.0
Version 6.0
Version 7.0
Version 8.0
Version 9.0
Version 4.0

References (4)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue Tracking
Source: secalert@redhat.com
Release Notes

Timeline

No history available yet.