cbcvebase.
CVE-2025-5918
published 2025-06-09

CVE-2025-5918: A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for…

medium6.6CVSS 3.1
AVLACLPRLUIRSUCHINAH
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
appleios_18.7.3_and_ipados
appleios_26.2_and_ipados
applemacos_sequoia
applemacos_sonoma
applemacos_tahoe
debianlibarchive< libarchive 3.4.3-2+deb11u3 (bullseye)libarchive 3.4.3-2+deb11u3 (bullseye)
libarchivelibarchive< 3.8.03.8.0
libarchivelibarchive>= 0 < 3.4.3-2+deb11u33.4.3-2+deb11u3
libarchivelibarchive>= 0 < 3.8.4-13.8.4-1
libarchivelibarchive>= 0 < 3.6.0-1ubuntu1.63.6.0-1ubuntu1.6
libarchivelibarchive>= 0 < 3.7.2-2ubuntu0.63.7.2-2ubuntu0.6
libarchivelibarchive>= 0 < 3.7.7-0ubuntu3.13.7.7-0ubuntu3.1
libarchivelibarchive>= 0 < 3.1.2-7ubuntu2.8+esm43.1.2-7ubuntu2.8+esm4
libarchivelibarchive>= 0 < 3.1.2-11ubuntu0.16.04.8+esm23.1.2-11ubuntu0.16.04.8+esm2
libarchivelibarchive>= 0 < 3.2.2-3.1ubuntu0.7+esm23.2.2-3.1ubuntu0.7+esm2
libarchivelibarchive>= 0 < 3.4.0-2ubuntu1.5+esm13.4.0-2ubuntu1.5+esm1
msrcazl3_cmake_3.30.3-8_on_azure_linux_3.0
msrcazl3_libarchive_3.7.7-2_on_azure_linux_3.0
msrcazl3_libarchive_3.7.7-3_on_azure_linux_3.0
msrccbl2_cmake_3.21.4-18_on_cbl_mariner_2.0
msrccbl2_cmake_3.21.4-19_on_cbl_mariner_2.0
msrccbl2_cmake_3.21.4-20_on_cbl_mariner_2.0
msrccbl2_libarchive_3.6.1-6_on_cbl_mariner_2.0
msrccbl2_libarchive_3.6.1-7_on_cbl_mariner_2.0
redhatenterprise_linux

CVSS provenance

nvdv3.16.6MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
osv6.6MEDIUM