CVE-2025-5916

Name
CVE-2025-5916
Description
A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vdb-entry https://access.redhat.com/security/cve/CVE-2025-5916
issue-tracking https://bugzilla.redhat.com/show_bug.cgi?id=2370872
secalert@redhat.com https://github.com/libarchive/libarchive/pull/2568
secalert@redhat.com https://github.com/libarchive/libarchive/releases/tag/v3.8.0

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:* libarchive >= None < 3.8.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libarchive edge-main 3.7.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive edge-main 3.7.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive edge-main 3.7.5-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive edge-main 3.7.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive edge-main 3.6.1-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive edge-main 3.6.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive edge-main 3.6.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive edge-main 3.5.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive edge-main 3.4.2-r0 None possibly vulnerable
libarchive edge-main 3.4.0-r0 None possibly vulnerable
libarchive edge-main 3.3.2-r1 None possibly vulnerable
libarchive 3.22-main 3.7.9-r0 None possibly vulnerable
libarchive 3.22-main 3.7.5-r0 None possibly vulnerable
libarchive 3.22-main 3.7.4-r0 None possibly vulnerable
libarchive 3.22-main 3.6.1-r2 None possibly vulnerable
libarchive 3.22-main 3.6.1-r0 None possibly vulnerable
libarchive 3.22-main 3.6.0-r0 None possibly vulnerable
libarchive 3.22-main 3.4.2-r0 None possibly vulnerable
libarchive 3.22-main 3.4.0-r0 None possibly vulnerable
libarchive 3.22-main 3.3.2-r1 None possibly vulnerable
libarchive 3.21-main 3.7.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive 3.21-main 3.7.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive 3.21-main 3.7.5-r0 None possibly vulnerable
libarchive 3.21-main 3.7.4-r0 None possibly vulnerable
libarchive 3.21-main 3.6.1-r2 None possibly vulnerable
libarchive 3.21-main 3.6.1-r0 None possibly vulnerable
libarchive 3.21-main 3.6.0-r0 None possibly vulnerable
libarchive 3.21-main 3.4.2-r0 None possibly vulnerable
libarchive 3.21-main 3.4.0-r0 None possibly vulnerable
libarchive 3.21-main 3.3.2-r1 None possibly vulnerable
libarchive 3.20-main 3.7.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive 3.20-main 3.7.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive 3.20-main 3.7.5-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive 3.20-main 3.7.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive 3.20-main 3.6.1-r2 None possibly vulnerable
libarchive 3.20-main 3.6.1-r0 None possibly vulnerable
libarchive 3.20-main 3.6.0-r0 None possibly vulnerable
libarchive 3.20-main 3.4.2-r0 None possibly vulnerable
libarchive 3.20-main 3.4.0-r0 None possibly vulnerable
libarchive 3.20-main 3.3.2-r1 None possibly vulnerable
libarchive 3.19-main 3.7.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive 3.19-main 3.7.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive 3.19-main 3.7.5-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive 3.19-main 3.7.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libarchive 3.19-main 3.6.1-r2 None possibly vulnerable
libarchive 3.19-main 3.6.1-r0 None possibly vulnerable
libarchive 3.19-main 3.6.0-r0 None possibly vulnerable
libarchive 3.19-main 3.4.2-r0 None possibly vulnerable
libarchive 3.19-main 3.4.0-r0 None possibly vulnerable
libarchive 3.19-main 3.3.2-r1 None possibly vulnerable