cbcvebase.
CVE-2025-5918
published 2025-06-09

CVE-2025-5918: A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for…

PriorityP427medium6.6CVSS 3.1
AVLACLPRLUIRSUCHINAH
EPSS
0.34%
26.3th percentile
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
appleios_18.7.3_and_ipados
appleios_26.2_and_ipados
applemacos_sequoia
applemacos_sonoma
applemacos_tahoe
debianlibarchive< libarchive 3.4.3-2+deb11u3 (bullseye)libarchive 3.4.3-2+deb11u3 (bullseye)
libarchivelibarchive< 3.8.03.8.0
libarchivelibarchive>= 0 < 3.4.3-2+deb11u33.4.3-2+deb11u3
libarchivelibarchive>= 0 < 3.8.4-13.8.4-1
libarchivelibarchive>= 0 < 3.6.0-1ubuntu1.63.6.0-1ubuntu1.6
libarchivelibarchive>= 0 < 3.7.2-2ubuntu0.63.7.2-2ubuntu0.6
libarchivelibarchive>= 0 < 3.7.7-0ubuntu3.13.7.7-0ubuntu3.1
libarchivelibarchive>= 0 < 3.1.2-7ubuntu2.8+esm43.1.2-7ubuntu2.8+esm4
libarchivelibarchive>= 0 < 3.1.2-11ubuntu0.16.04.8+esm23.1.2-11ubuntu0.16.04.8+esm2
libarchivelibarchive>= 0 < 3.2.2-3.1ubuntu0.7+esm23.2.2-3.1ubuntu0.7+esm2
libarchivelibarchive>= 0 < 3.4.0-2ubuntu1.5+esm13.4.0-2ubuntu1.5+esm1
msrcazl3_cmake_3.30.3-8_on_azure_linux_3.0
msrcazl3_libarchive_3.7.7-2_on_azure_linux_3.0
msrcazl3_libarchive_3.7.7-3_on_azure_linux_3.0
msrccbl2_cmake_3.21.4-18_on_cbl_mariner_2.0
msrccbl2_cmake_3.21.4-19_on_cbl_mariner_2.0
msrccbl2_cmake_3.21.4-20_on_cbl_mariner_2.0
msrccbl2_libarchive_3.6.1-6_on_cbl_mariner_2.0
msrccbl2_libarchive_3.6.1-7_on_cbl_mariner_2.0
redhatenterprise_linux

CVSS provenance

nvdv3.16.6MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
osv6.6MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian3.9LOW
vendor_msrc3.9LOW
vendor_redhat3.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.