CVE-2025-25724
published 2025-03-02CVE-2025-25724: list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
25.9th percentile
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libarchive | < libarchive 3.8.4-1 (forky) | libarchive 3.8.4-1 (forky) |
| libarchive | libarchive | <= 3.7.7 | — |
| libarchive | libarchive | >= 0 < 3.8.4-1 | 3.8.4-1 |
| libarchive | libarchive | >= 0 < 3.4.0-2ubuntu1.5 | 3.4.0-2ubuntu1.5 |
| libarchive | libarchive | >= 0 < 3.6.0-1ubuntu1.4 | 3.6.0-1ubuntu1.4 |
| libarchive | libarchive | >= 0 < 3.6.0-1ubuntu1.6 | 3.6.0-1ubuntu1.6 |
| libarchive | libarchive | >= 0 < 3.7.2-2ubuntu0.4 | 3.7.2-2ubuntu0.4 |
| libarchive | libarchive | >= 0 < 3.7.2-2ubuntu0.6 | 3.7.2-2ubuntu0.6 |
| libarchive | libarchive | >= 0 < 3.7.7-0ubuntu3.1 | 3.7.7-0ubuntu3.1 |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.8+esm4 | 3.1.2-7ubuntu2.8+esm4 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.8+esm2 | 3.1.2-11ubuntu0.16.04.8+esm2 |
| libarchive | libarchive | >= 0 < 3.2.2-3.1ubuntu0.7+esm2 | 3.2.2-3.1ubuntu0.7+esm2 |
| libarchive | libarchive | >= 0 < 3.4.0-2ubuntu1.5+esm1 | 3.4.0-2ubuntu1.5+esm1 |
| msrc | azl3_libarchive_3.7.7-2_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libarchive_3.6.1-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libarchive_3.6.1-6_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_oracle7.8MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian4.0LOW
vendor_msrc4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libarchive vulnerabilities
osv·2026-04-02·CVSS 5.5
CVE-2019-19221 [MEDIUM] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive incorrectly handled certain archive
files. An attacker could possibly use this issue to access sensitive
information. This issue only affected Ubuntu 14.04 LTS. (CVE-2019-19221)
It was discovered that libarchive incorrectly handled certain RAR archive
files. If a user or automated system were tricked into processing a
specially crafted RAR archive, an attacker could possibly use this issue to
cause libarchive to crash, resulting in a denial of service, or execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS
and Ubuntu 18.04 LTS. (CVE-2024-20696)
It was discovered that libarchive incorrectly handled certain RAR archive
files. An attacker could possibly use this issue to execute arbitrary code
or c
OSV
libarchive vulnerabilities
osv·2025-04-23·CVSS 4.8
CVE-2025-1632 [MEDIUM] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that the libarchive bsdunzip utility incorrectly handled
certain ZIP archive files. If a user or automated system were tricked into
processing a specially crafted ZIP archive, an attacker could use this
issue to cause libarchive to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS,
Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-1632)
It was discovered that libarchive incorrectly handled certain TAR archive
files. If a user or automated system were tricked into processing a
specially crafted TAR archive, an attacker could use this issue to cause
libarchive to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-25724)
OSV
CVE-2025-25724: list_item_verbose in tar/util
osv·2025-03-02·CVSS 7.8
CVE-2025-25724 [HIGH] CVE-2025-25724: list_item_verbose in tar/util
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.
GHSA
GHSA-722w-734r-qg74: list_item_verbose in tar/util
ghsa_unreviewed·2025-03-02
CVE-2025-25724 [MEDIUM] CWE-252 GHSA-722w-734r-qg74: list_item_verbose in tar/util
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2026-04-02·CVSS 5.5
CVE-2025-5916 [MEDIUM] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: Several security issues were fixed in libarchive.
It was discovered that libarchive incorrectly handled certain archive
files. An attacker could possibly use this issue to access sensitive
information. This issue only affected Ubuntu 14.04 LTS. (CVE-2019-19221)
It was discovered that libarchive incorrectly handled certain RAR archive
files. If a user or automated system were tricked into processing a
specially crafted RAR archive, an attacker could possibly use this issue to
cause libarchive to crash, resulting in a denial of service, or execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS
and Ubuntu 18.04 LTS. (CVE-2024-20696)
It was discovered that libarchive incorrectly handled certain RAR archive
files. An at
Oracle
Oracle Oracle Communications Risk Matrix: Core (libarchive) — CVE-2025-25724
vendor_oracle·2025-10-15·CVSS 7.8
CVE-2025-25724 [MEDIUM] Oracle Oracle Communications Risk Matrix: Core (libarchive) — CVE-2025-25724
Oracle Oracle Communications Risk Matrix: Core (libarchive) vulnerability
CVE: CVE-2025-25724
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2025 (OCT 2025)
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2025-04-23·CVSS 3.3
CVE-2025-25724 [LOW] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: Several security issues were fixed in libarchive.
It was discovered that the libarchive bsdunzip utility incorrectly handled
certain ZIP archive files. If a user or automated system were tricked into
processing a specially crafted ZIP archive, an attacker could use this
issue to cause libarchive to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS,
Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-1632)
It was discovered that libarchive incorrectly handled certain TAR archive
files. If a user or automated system were tricked into processing a
specially crafted TAR archive, an attacker could use this issue to cause
libarchive to crash, resulting in a denial of service, or possibly exec
Microsoft
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is
vendor_msrc·2025-03-11·CVSS 4.0
CVE-2025-25724 [MEDIUM] CWE-252 list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025.
Red Hat
libarchive: Buffer Overflow vulnerability in libarchive
vendor_redhat·2025-03-02·CVSS 4.0
CVE-2025-25724 [MEDIUM] CWE-252 libarchive: Buffer Overflow vulnerability in libarchive
libarchive: Buffer Overflow vulnerability in libarchive
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.
A flaw was found in the libarchive package. Affected versions of libarchive do not check a strftime return value, which can lead to a denial of service or unspecified other impacts via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.
Statement: Red Hat employs static and dynamic security testing and numerous program hardening technologies as
Debian
CVE-2025-25724: libarchive - list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an st...
vendor_debian·2025·CVSS 4.0
CVE-2025-25724 [MEDIUM] CVE-2025-25724: libarchive - list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an st...
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.8.4-1)
sid: resolved (fixed in 3.8.4-1)
trixie: open
No detection rules found.
No public exploits indexed.
2025-03-02
Published