ZeroHour

CVE-2025-5918

CVSS 3.1
6.6 medium
EPSS
<1%p29
Published
()
Modified
Description

A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.

Vendors
libarchiveredhat
Products
libarchive, openshift container platform, enterprise linux
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.