CVE-2025-1632
published 2025-02-24CVE-2025-1632: A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.32%
24.1th percentile
A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libarchive | < libarchive 3.7.4-2 (forky) | libarchive 3.7.4-2 (forky) |
| libarchive | libarchive | <= 3.7.7 | — |
| libarchive | libarchive | — | — |
| libarchive | libarchive | — | — |
| libarchive | libarchive | — | — |
| libarchive | libarchive | — | — |
| libarchive | libarchive | — | — |
| libarchive | libarchive | — | — |
| libarchive | libarchive | — | — |
| libarchive | libarchive | — | — |
| libarchive | libarchive | >= 0 < 3.7.4-2 | 3.7.4-2 |
| libarchive | libarchive | >= 0 < 3.7.4-2 | 3.7.4-2 |
| libarchive | libarchive | >= 0 < 3.4.0-2ubuntu1.5 | 3.4.0-2ubuntu1.5 |
| libarchive | libarchive | >= 0 < 3.6.0-1ubuntu1.4 | 3.6.0-1ubuntu1.4 |
| libarchive | libarchive | >= 0 < 3.7.2-2ubuntu0.4 | 3.7.2-2ubuntu0.4 |
| msrc | azl3_libarchive_3.7.7-2_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.04.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
osv4.8MEDIUM
vendor_debian4.8LOW
vendor_redhat4.8MEDIUM
vendor_msrc3.3LOW
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2025-04-23·CVSS 3.3
CVE-2025-25724 [LOW] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: Several security issues were fixed in libarchive.
It was discovered that the libarchive bsdunzip utility incorrectly handled
certain ZIP archive files. If a user or automated system were tricked into
processing a specially crafted ZIP archive, an attacker could use this
issue to cause libarchive to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS,
Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-1632)
It was discovered that libarchive incorrectly handled certain TAR archive
files. If a user or automated system were tricked into processing a
specially crafted TAR archive, an attacker could use this issue to cause
libarchive to crash, resulting in a denial of service, or possibly exec
Red Hat
libarchive: null pointer dereference in bsdunzip.c
vendor_redhat·2025-02-24·CVSS 4.8
CVE-2025-1632 [MEDIUM] CWE-476 libarchive: null pointer dereference in bsdunzip.c
libarchive: null pointer dereference in bsdunzip.c
A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A flaw was found in the bsdunzip utility of libarchive. In affected versions, a specially crafted file may trigger a null pointer dereference. This issue can lead to an application crash or other unexpected behavior. This bug does not compromise the integrity or availability of the base system.
Package: libarchive (Red Hat Enterprise Linux 10)
Microsoft
libarchive bsdunzip.c list null pointer dereference
vendor_msrc·2025-02-11·CVSS 3.3
CVE-2025-1632 [MEDIUM] CWE-476 libarchive bsdunzip.c list null pointer dereference
libarchive bsdunzip.c list null pointer dereference
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
VulDB: VulDB
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.mic
Debian
CVE-2025-1632: libarchive - A vulnerability was found in libarchive up to 3.7.7. It has been classified as p...
vendor_debian·2025·CVSS 4.8
CVE-2025-1632 [MEDIUM] CVE-2025-1632: libarchive - A vulnerability was found in libarchive up to 3.7.7. It has been classified as p...
A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.7.4-2)
sid: resolved (fixed in 3.7.4-2)
trixie: resolved (fixed in 3.7.4-2)
OSV
libarchive vulnerabilities
osv·2025-04-23·CVSS 4.8
CVE-2025-1632 [MEDIUM] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that the libarchive bsdunzip utility incorrectly handled
certain ZIP archive files. If a user or automated system were tricked into
processing a specially crafted ZIP archive, an attacker could use this
issue to cause libarchive to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS,
Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-1632)
It was discovered that libarchive incorrectly handled certain TAR archive
files. If a user or automated system were tricked into processing a
specially crafted TAR archive, an attacker could use this issue to cause
libarchive to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-25724)
OSV
CVE-2025-1632: A vulnerability was found in libarchive up to 3
osv·2025-02-24·CVSS 4.8
CVE-2025-1632 [MEDIUM] CVE-2025-1632: A vulnerability was found in libarchive up to 3
A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA
GHSA-cw9m-pj72-3cj5: A vulnerability was found in libarchive up to 3
ghsa_unreviewed·2025-02-24
CVE-2025-1632 [MEDIUM] CWE-404 GHSA-cw9m-pj72-3cj5: A vulnerability was found in libarchive up to 3
A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-24
Published