PT-2025-24554 · Unknown+6 · Libarchive+6
Carnil
·
Published
2025-05-11
·
Updated
2025-09-29
·
CVE-2025-5915
CVSS v3.1
6.6
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libarchive (affected versions not specified)
Description
A flaw in the libarchive library can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This can cause the library to attempt to read beyond the allocated memory buffer, resulting in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Red Os
Suse
Ubuntu
Libarchive