CVE-2025-5917

A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.8 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
redhatCNA
2.8 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
CISA-ADPADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
Debian logo
Debian Releases
Debian Product
Codename
libarchive
bullseye
postponed
bookworm
no-dsa
bullseye (security)
vulnerable
bookworm (security)
vulnerable
trixie
vulnerable
sid
3.7.4-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libarchive
plucky
Fixed 3.7.7-0ubuntu2.3
released
oracular
Fixed 3.7.4-1ubuntu0.3
released
noble
Fixed 3.7.2-2ubuntu0.5
released
jammy
Fixed 3.6.0-1ubuntu1.5
released
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
needs-triage