CVE-2025-5918
published 2025-06-09CVE-2025-5918: A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for…
PriorityP427medium6.6CVSS 3.1
AVLACLPRLUIRSUCHINAH
EPSS
0.34%
26.3th percentile
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.7.3_and_ipados | — | — |
| apple | ios_26.2_and_ipados | — | — |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_tahoe | — | — |
| debian | libarchive | < libarchive 3.4.3-2+deb11u3 (bullseye) | libarchive 3.4.3-2+deb11u3 (bullseye) |
| libarchive | libarchive | < 3.8.0 | 3.8.0 |
| libarchive | libarchive | >= 0 < 3.4.3-2+deb11u3 | 3.4.3-2+deb11u3 |
| libarchive | libarchive | >= 0 < 3.8.4-1 | 3.8.4-1 |
| libarchive | libarchive | >= 0 < 3.6.0-1ubuntu1.6 | 3.6.0-1ubuntu1.6 |
| libarchive | libarchive | >= 0 < 3.7.2-2ubuntu0.6 | 3.7.2-2ubuntu0.6 |
| libarchive | libarchive | >= 0 < 3.7.7-0ubuntu3.1 | 3.7.7-0ubuntu3.1 |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.8+esm4 | 3.1.2-7ubuntu2.8+esm4 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.8+esm2 | 3.1.2-11ubuntu0.16.04.8+esm2 |
| libarchive | libarchive | >= 0 < 3.2.2-3.1ubuntu0.7+esm2 | 3.2.2-3.1ubuntu0.7+esm2 |
| libarchive | libarchive | >= 0 < 3.4.0-2ubuntu1.5+esm1 | 3.4.0-2ubuntu1.5+esm1 |
| msrc | azl3_cmake_3.30.3-8_on_azure_linux_3.0 | — | — |
| msrc | azl3_libarchive_3.7.7-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_libarchive_3.7.7-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_cmake_3.21.4-18_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_cmake_3.21.4-19_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_cmake_3.21.4-20_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libarchive_3.6.1-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libarchive_3.6.1-7_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.6MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
osv6.6MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian3.9LOW
vendor_msrc3.9LOW
vendor_redhat3.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2026-04-02·CVSS 5.5
CVE-2025-5916 [MEDIUM] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: Several security issues were fixed in libarchive.
It was discovered that libarchive incorrectly handled certain archive
files. An attacker could possibly use this issue to access sensitive
information. This issue only affected Ubuntu 14.04 LTS. (CVE-2019-19221)
It was discovered that libarchive incorrectly handled certain RAR archive
files. If a user or automated system were tricked into processing a
specially crafted RAR archive, an attacker could possibly use this issue to
cause libarchive to crash, resulting in a denial of service, or execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS
and Ubuntu 18.04 LTS. (CVE-2024-20696)
It was discovered that libarchive incorrectly handled certain RAR archive
files. An at
Apple
CVE-2025-5918: macOS Tahoe 26.2
vendor_apple·2025-12-12·CVSS 3.9
CVE-2025-5918 [LOW] CVE-2025-5918: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2025-5918
Component: CVE-2025-5918
Apple
CVE-2025-5918: iOS 18.7.3 and iPadOS 18.7.3
vendor_apple·2025-12-12·CVSS 3.9
CVE-2025-5918 [LOW] CVE-2025-5918: iOS 18.7.3 and iPadOS 18.7.3
Apple Security Update: About the security content of iOS 18.7.3 and iPadOS 18.7.3
Product: iOS 18.7.3 and iPadOS
Version: 18.7.3
CVE: CVE-2025-5918
Component: CVE-2025-5918
Apple
CVE-2025-5918: macOS Sonoma 14.8.3
vendor_apple·2025-12-12·CVSS 3.9
CVE-2025-5918 [LOW] CVE-2025-5918: macOS Sonoma 14.8.3
Apple Security Update: About the security content of macOS Sonoma 14.8.3
Product: macOS Sonoma
Version: 14.8.3
CVE: CVE-2025-5918
Component: CVE-2025-5918
Apple
CVE-2025-5918: macOS Sequoia 15.7.3
vendor_apple·2025-12-12·CVSS 3.9
CVE-2025-5918 [LOW] CVE-2025-5918: macOS Sequoia 15.7.3
Apple Security Update: About the security content of macOS Sequoia 15.7.3
Product: macOS Sequoia
Version: 15.7.3
CVE: CVE-2025-5918
Component: CVE-2025-5918
Apple
CVE-2025-5918: iOS 26.2 and iPadOS 26.2
vendor_apple·2025-12-12·CVSS 3.9
CVE-2025-5918 [LOW] CVE-2025-5918: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-5918
Component: CVE-2025-5918
Microsoft
Libarchive: reading past eof may be triggered for piped file streams
vendor_msrc·2025-06-10·CVSS 3.9
CVE-2025-5918 [LOW] CWE-125 Libarchive: reading past eof may be triggered for piped file streams
Libarchive: reading past eof may be triggered for piped file streams
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference
Red Hat
libarchive: Reading past EOF may be triggered for piped file streams
vendor_redhat·2025-05-20·CVSS 3.9
CVE-2025-5918 [LOW] CWE-125 libarchive: Reading past EOF may be triggered for piped file streams
libarchive: Reading past EOF may be triggered for piped file streams
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
Statement: This vulnerability is rat
Debian
CVE-2025-5918: libarchive - A vulnerability has been identified in the libarchive library. This flaw can be ...
vendor_debian·2025·CVSS 3.9
CVE-2025-5918 [LOW] CVE-2025-5918: libarchive - A vulnerability has been identified in the libarchive library. This flaw can be ...
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.4.3-2+deb11u3)
forky: resolved (fixed in 3.8.4-1)
sid: resolved (fixed in 3.8.4-1)
trixie: open
OSV
libarchive vulnerabilities
osv·2026-04-02·CVSS 5.5
CVE-2019-19221 [MEDIUM] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive incorrectly handled certain archive
files. An attacker could possibly use this issue to access sensitive
information. This issue only affected Ubuntu 14.04 LTS. (CVE-2019-19221)
It was discovered that libarchive incorrectly handled certain RAR archive
files. If a user or automated system were tricked into processing a
specially crafted RAR archive, an attacker could possibly use this issue to
cause libarchive to crash, resulting in a denial of service, or execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS
and Ubuntu 18.04 LTS. (CVE-2024-20696)
It was discovered that libarchive incorrectly handled certain RAR archive
files. An attacker could possibly use this issue to execute arbitrary code
or c
OSV
CVE-2025-5918: A vulnerability has been identified in the libarchive library
osv·2025-06-09·CVSS 6.6
CVE-2025-5918 [MEDIUM] CVE-2025-5918: A vulnerability has been identified in the libarchive library
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
GHSA
GHSA-3hqh-8h99-q2cf: A vulnerability has been identified in the libarchive library
ghsa_unreviewed·2025-06-09
CVE-2025-5918 [LOW] CWE-125 GHSA-3hqh-8h99-q2cf: A vulnerability has been identified in the libarchive library
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-5918 rpi-imager: Reading past EOF may be triggered for piped file streams [fedora-42]
bugzilla·2025-06-09·CVSS 6.6
CVE-2025-5918 [MEDIUM] CVE-2025-5918 rpi-imager: Reading past EOF may be triggered for piped file streams [fedora-42]
CVE-2025-5918 rpi-imager: Reading past EOF may be triggered for piped file streams [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2370877
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of
Bugzilla
CVE-2025-5918 mingw-libarchive: Reading past EOF may be triggered for piped file streams [fedora-42]
bugzilla·2025-06-09·CVSS 6.6
CVE-2025-5918 [MEDIUM] CVE-2025-5918 mingw-libarchive: Reading past EOF may be triggered for piped file streams [fedora-42]
CVE-2025-5918 mingw-libarchive: Reading past EOF may be triggered for piped file streams [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2370877
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'versio
2025-06-09
Published