CVE-2025-5914
🟡 Monitoruj
Przepełnienie całkowitej liczby w libarchive prowadzi do podwójnego zwolnienia pamięci.
CVSS
7.8
EPSS
0.4%
Exploit
poc
Vendor
redhat
Opis źródłowy (NVD)
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2025-06-09 20:15:26 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 04:17:33 UTC |
Referencje
- https://access.redhat.com/errata/RHSA-2025:14130 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:14135 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:14137 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:14141 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:14142 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:14525 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:14528 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:14594 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:14644 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:14808 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:14810 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:14828 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:15024 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:15397 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:15709 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:15827 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:15828 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:16524 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:18217 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:18218 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:18219 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:19041 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:19046 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:21885 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:21913 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2026:0326 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2026:0934 ([email protected])
- https://access.redhat.com/errata/RHSA-2026:1541 ([email protected])
- https://access.redhat.com/security/cve/CVE-2025-5914 ([email protected]) [Third Party Advisory]
- https://bugzilla.redhat.com/show_bug.cgi?id=2370861 ([email protected]) [Issue Tracking, Third Party Advisory]
- https://github.com/libarchive/libarchive/pull/2598 ([email protected]) [Exploit, Issue Tracking, Patch]
- https://github.com/libarchive/libarchive/releases/tag/v3.8.0 ([email protected]) [Release Notes]
- https://cert-portal.siemens.com/productcert/html/ssa-585531.html (0b142b55-0307-4c5a-b3c9-f314f3fb7c5e)