cbcvebase.
CVE-2025-25724
published 2025-03-02

CVE-2025-25724: list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
25.9th percentile
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlibarchive< libarchive 3.8.4-1 (forky)libarchive 3.8.4-1 (forky)
libarchivelibarchive<= 3.7.7
libarchivelibarchive>= 0 < 3.8.4-13.8.4-1
libarchivelibarchive>= 0 < 3.4.0-2ubuntu1.53.4.0-2ubuntu1.5
libarchivelibarchive>= 0 < 3.6.0-1ubuntu1.43.6.0-1ubuntu1.4
libarchivelibarchive>= 0 < 3.6.0-1ubuntu1.63.6.0-1ubuntu1.6
libarchivelibarchive>= 0 < 3.7.2-2ubuntu0.43.7.2-2ubuntu0.4
libarchivelibarchive>= 0 < 3.7.2-2ubuntu0.63.7.2-2ubuntu0.6
libarchivelibarchive>= 0 < 3.7.7-0ubuntu3.13.7.7-0ubuntu3.1
libarchivelibarchive>= 0 < 3.1.2-7ubuntu2.8+esm43.1.2-7ubuntu2.8+esm4
libarchivelibarchive>= 0 < 3.1.2-11ubuntu0.16.04.8+esm23.1.2-11ubuntu0.16.04.8+esm2
libarchivelibarchive>= 0 < 3.2.2-3.1ubuntu0.7+esm23.2.2-3.1ubuntu0.7+esm2
libarchivelibarchive>= 0 < 3.4.0-2ubuntu1.5+esm13.4.0-2ubuntu1.5+esm1
msrcazl3_libarchive_3.7.7-2_on_azure_linux_3.0
msrccbl2_libarchive_3.6.1-5_on_cbl_mariner_2.0
msrccbl2_libarchive_3.6.1-6_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_oracle7.8MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian4.0LOW
vendor_msrc4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.